Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Ctlertxt' = '{73E6E8C4-22C7-4205-9AFD-65677618936B}'
- <SYSTEM32>\hexurbin.dll
- <SYSTEM32>\apiwu3d.dll
- <SYSTEM32>\magewwin\manulsap\dirobuni.dll
- %TEMP%\_is132875.ini
- <SYSTEM32>\mecimid.dll
- %TEMP%\UUU2.tmp
- %TEMP%\UUU1.tmp
- <SYSTEM32>\comigzip32.dll
- <SYSTEM32>\decelvid.dll
- %TEMP%\UUU3.tmp
- %TEMP%\UUU3.tmp
- %TEMP%\_is132875.ini
- %TEMP%\UUU1.tmp
- %TEMP%\UUU2.tmp