Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windoze' = '"%TEMP%\716212."'
- <SYSTEM32>\ntvdm.exe -f -i2
- <SYSTEM32>\ntvdm.exe -f -i1
- %WINDIR%\Temp\scs4.tmp
- %WINDIR%\Temp\scs3.tmp
- %TEMP%\is-215U0.tmp\is-GJ9EK.tmp
- %TEMP%\is-RP8TG.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-RP8TG.tmp\_isetup\_RegDLL.tmp
- %TEMP%\8587000.exe
- %TEMP%\445782.exe
- %TEMP%\716212
- %TEMP%\2179311.com
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs3.tmp
- %WINDIR%\Temp\scs4.tmp
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs2.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-ae8.aec.3a0002'
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-ad4.ad8.390001'