Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Keyboard Inf.' = '%APPDATA%\Roaming\Identities\pools.exe'
- '%APPDATA%\Roaming\Identities\pools.exe'
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\6P5SDOMI\raw[1].php
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\YF7T7AK2\raw[1].php
- %APPDATA%\Roaming\Identities\IMG_61846_359718.jpg
- C:\ProgramData\Microsoft\RAC\Temp\sqlB318.tmp
- %APPDATA%\Roaming\Identities\pools.exe
- C:\ProgramData\Microsoft\RAC\Temp\sqlB348.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlB318.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sqlB348.tmp
- 'pa###bin.com':80
- pa###bin.com/raw.php?i=########
- DNS ASK pa###bin.com
- ClassName: 'Indicator' WindowName: '(null)'