Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5460C4DF-B266-909E-CB58-E32B79832EB2}] 'StubPath' = '%WINDIR%\InstallDir\Server.exe restart'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{5460C4DF-B266-909E-CB58-E32B79832EB2}] 'StubPath' = '%WINDIR%\InstallDir\Server.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HKCU' = '%WINDIR%\InstallDir\Server.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,,%ProgramFiles%\ebaurodr\mhrhcrji.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HKLM' = '%WINDIR%\InstallDir\Server.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\mhrhcrji.exe
- C:\Far2\Plugins\FTP\FarFtp.dll
- C:\Far2\Plugins\HlfViewer\HlfViewer.dll
- C:\Far2\Plugins\FarCmds\FARCmds.dll
- C:\Far2\Plugins\DrawLine\DrawLine.dll
- C:\Far2\Plugins\EMenu\EMenu.dll
- C:\Far2\Plugins\TmpPanel\TmpPanel.dll
- C:\Far2\Plugins\WinSCP\WinSCP.dll
- C:\Far2\Plugins\ProcList\Proclist.dll
- C:\Far2\Plugins\MacroView\MacroView.dll
- C:\Far2\Plugins\Network\Network.dll
- C:\Far2\FExcept\FExcept.dll
- C:\Far2\Plugins\7-Zip\7-ZipFar.dll
- C:\Far2\FExcept\ExcDump.dll
- C:\Far2\Far.exe
- C:\Far2\FExcept\demangle32.dll
- C:\Far2\Plugins\Colorer\bin\colorer.dll
- C:\Far2\Plugins\Compare\Compare.dll
- C:\Far2\Plugins\Brackets\Brackets.dll
- C:\Far2\Plugins\arclite\7z.dll
- C:\Far2\Plugins\arclite\arclite.dll
- <Имя диска съемного носителя>:\RECYCLER\S-1-4-26-5734026877-1786765000-823325755-0722\KQvqfKKC.cpl
- <Имя диска съемного носителя>:\autorun.inf
- <Имя диска съемного носителя>:\RECYCLER\S-1-4-26-5734026877-1786765000-823325755-0722\wEgZCmsI.exe
- '%TEMP%\getmonyplanetwin365.exe'
- '%TEMP%\Project1.exe'
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'
- '<SYSTEM32>\svchost.exe'
- '%TEMP%\getmonyplanetwin365mgr.exe'
- <SYSTEM32>\svchost.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\1234567890[1].functions
- %WINDIR%\InstallDir\Server.exe
- %ProgramFiles%\ebaurodr\mhrhcrji.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\1234567890[1].functions
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\1234567890[1].functions
- %APPDATA%\Microsoft\Windows\--((Mutex))--.xtr
- %TEMP%\getmonyplanetwin365mgr.exe
- %TEMP%\getmonyplanetwin365.exe
- %TEMP%\Project1.exe
- %ProgramFiles%\Internet Explorer\dmlconf.dat
- %TEMP%\~TM2.tmp
- %TEMP%\~TM1.tmp
- %HOMEPATH%\Start Menu\Programs\Startup\mhrhcrji.exe
- %APPDATA%\Microsoft\Windows\--((Mutex))--.xtr
- %TEMP%\~TM2.tmp
- %TEMP%\~TM1.tmp
- %APPDATA%\Microsoft\Windows\--((Mutex))--.xtr
- 'po###liks.com':443
- 'pr###liks.com':443
- 'fk#####feew32233.com':443
- 'jd#####fw3232234.com':443
- 'fd#####we3093443.com':443
- 'st###oliks.com':443
- '74.##5.232.51':80
- 'localhost':1043
- 'localhost':80
- 'mr##.no-ip.biz':80
- http://12#.0.0.1/1234567890.functions via localhost
- http://mr##.no-ip.biz/1234567890.functions
- DNS ASK fk#####feew32233.com
- DNS ASK po###liks.com
- DNS ASK jd#####fw3232234.com
- DNS ASK fd#####we3093443.com
- DNS ASK st###oliks.com
- DNS ASK google.com
- DNS ASK pr###liks.com
- DNS ASK mr##.no-ip.biz
- ClassName: 'Shell_TrayWnd' WindowName: ''