Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'y21998e2' = '%HOMEPATH%\y21998e2\44617.vbs'
- '%HOMEPATH%\y21998e2\ZiQECoyKzToj.com' jGPzOPmSDZB
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %HOMEPATH%\y21998e2\tcFO.CKG
- %HOMEPATH%\y21998e2\39825.cmd
- %HOMEPATH%\y21998e2\44617.vbs
- %HOMEPATH%\y21998e2\pxjVDCV.BSO
- %HOMEPATH%\y21998e2\ZiQECoyKzToj.com
- %HOMEPATH%\y21998e2\jGPzOPmSDZB
- %HOMEPATH%\y21998e2\tcFO.CKG
- %HOMEPATH%\y21998e2\44617.vbs
- %HOMEPATH%\y21998e2\39825.cmd
- %HOMEPATH%\y21998e2\pxjVDCV.BSO
- %HOMEPATH%\y21998e2\ZiQECoyKzToj.com
- %HOMEPATH%\y21998e2\jGPzOPmSDZB
- 'an###king.net':3333
- DNS ASK an###king.net
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'