Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = '%HOMEPATH%\Svchost.exe,explorer.exe'
- '%TEMP%\Cvchost.exe'
- %TEMP%\aut3.tmp
- %HOMEPATH%\Svchost.exe
- %HOMEPATH%\log-kailog.html
- %TEMP%\wacoulv
- %TEMP%\erqjrgn
- %TEMP%\aut1.tmp
- %TEMP%\Cvchost.exe
- %TEMP%\aut2.tmp
- %HOMEPATH%\Svchost.exe
- %TEMP%\aut3.tmp
- %TEMP%\wacoulv
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\erqjrgn