Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '*gXp5lJQ' = ''
- <SYSTEM32>\rundll32.exe "%HOMEPATH%\Local Settings\r7uPmylz\jYzNydZT.XNP",F1fe768
- <SYSTEM32>\cscript.exe
- <Служебный элемент>
- <SYSTEM32>\ctfmon.exe
- %WINDIR%\Explorer.EXE
- [<HKCU>\Software\Google\Google Talk\Accounts]
- [<HKCU>\Software\Paltalk]
- <SYSTEM32>\rundll32.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE
- %HOMEPATH%\Local Settings\r7uPmylz\8dNVqc7r.pVU
- %HOMEPATH%\Local Settings\r7uPmylz\KbYda-C6.gdy
- %HOMEPATH%\Local Settings\r7uPmylz\auGx_Pp2.3xi
- %HOMEPATH%\Local Settings\r7uPmylz\jYzNydZT.XNP
- %HOMEPATH%\Local Settings\r7uPmylz\40CWzTk3.8W2
- 'wp#d':80
- wp#d/wpad.dat
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: ''