Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '4ge9wk2b528a898' = '%HOMEPATH%\4ge9wk2b528a898\55688.vbs'
- '%HOMEPATH%\4ge9wk2b528a898\bot.exe'
- '%HOMEPATH%\4ge9wk2b528a898\OSboot.exe' pYuPU.ZPY
- %HOMEPATH%\4ge9wk2b528a898\89323.cmd
- %HOMEPATH%\4ge9wk2b528a898\bot.exe
- %HOMEPATH%\4ge9wk2b528a898\dl.txt
- %HOMEPATH%\4ge9wk2b528a898\55688.vbs
- %HOMEPATH%\4ge9wk2b528a898\OSboot.exe
- %HOMEPATH%\4ge9wk2b528a898\kqqiD.FVX
- %HOMEPATH%\4ge9wk2b528a898\QZzteea.AEA
- %HOMEPATH%\4ge9wk2b528a898\pYuPU.ZPY
- %HOMEPATH%\4ge9wk2b528a898\QZzteea.AEA
- %HOMEPATH%\4ge9wk2b528a898\55688.vbs
- %HOMEPATH%\4ge9wk2b528a898\89323.cmd
- %HOMEPATH%\4ge9wk2b528a898\kqqiD.FVX
- %HOMEPATH%\4ge9wk2b528a898\OSboot.exe
- %HOMEPATH%\4ge9wk2b528a898\pYuPU.ZPY
- 'on####ve.live.com':443
- DNS ASK on####ve.live.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'