Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LocalRes.exe' = '%PROGRAM_FILES%\WindowsUpdate\LocalRes.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'execute.exe' = '<LS_APPDATA>\execute.exe'
- '%PROGRAM_FILES%\WindowsUpdate\LocalRes.exe'
- '<LS_APPDATA>\execute.exe'
- '%HOMEPATH%\Desktop\MusicLib.exe'
- firefox.exe
- iexplore.exe
- chrome.exe
- magent.exe
- %PROGRAM_FILES%\WindowsUpdate\LocalRes.exe
- %APPDATA%\Local\Google\Chrome\User Data\Default\google chrome.exe
- %HOMEPATH%\Desktop\MusicLib.exe
- <LS_APPDATA>\execute.exe
- 'm.###class.com':80
- 'wp#d':80
- m.###class.com/reg.php?un######################
- wp#d/wpad.dat
- DNS ASK m.###class.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''