Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'FlashUpdate' = '%WINDIR%\exFlash\FlashPlayer.exe'
- Средство контроля пользовательских учетных записей (UAC)
- '<SYSTEM32>\wermgr.exe' -queuereporting
- '<SYSTEM32>\taskhost.exe' $(Arg0)
- C:\ProgramData\Microsoft\RAC\Temp\sql8516.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sql8536.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlC68A.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlC66A.tmp
- %WINDIR%\exFlash\king.txt
- %WINDIR%\exFlash\FlashPlayer.exe
- %WINDIR%\exFlash\setup.xml
- %WINDIR%\exFlash\MZђ
- C:\ProgramData\Microsoft\RAC\Temp\sql8516.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sql8536.tmp
- 'so###lmsn.com':80
- so###lmsn.com/MZ?
- so###lmsn.com/king.txt
- DNS ASK so###lmsn.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'