Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Proxy Config Tool for Windows' = '%CommonProgramFiles%\system\proxycfg.exe'
- %CommonProgramFiles%\System\proxycfg.exe
- C:\juegos\autobus.exe
- [<HKLM>\SOFTWARE\ORL\WinVNC3]
- [<HKCU>\Software\ORL\WinVNC3]
- %CommonProgramFiles%\System\VNCHooks.dll
- C:\juegos\autobus.exe
- C:\juegos\flashpong.swf
- %TEMP%\gert0.dll
- %TEMP%\ci0-temp\remote desktop.set
- %CommonProgramFiles%\System\proxycfg.exe
- %TEMP%\gert0.dll
- %TEMP%\ci0-temp\remote desktop.set
- 'localhost':5900
- ClassName: 'Shell_TrayWnd' WindowName: ''