Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'MtYhwr' = 'C:\MtYhwrMtYhwr\MtYhwr.vbs'
- '%APPDATA%\n2okd\8fwls.exe'
- '%TEMP%\177.exe'
- '%TEMP%\177.exe' (загружен из сети Интернет)
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe'
- '%APPDATA%\n2okd\8fwls.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe
- 8fwls.exe
- C:\MtYhwrMtYhwr\MtYhwr.exe
- C:\MtYhwrMtYhwr\x
- %APPDATA%\Microsoft\Windows\zUB8dknwC\zUB8dknwC.nfo
- %APPDATA%\Microsoft\Windows\zUB8dknwC\zUB8dknwC.svr
- %APPDATA%\Microsoft\Windows\zUB8dknwC\zUB8dknwC.dat
- C:\MtYhwrMtYhwr\MtYhwr.vbs
- %APPDATA%\n2okd\x
- %APPDATA%\n2okd\8fwls.exe
- %APPDATA%\MtYhwr
- %TEMP%\177.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\0ff1c3v4l1dKey2017[1].exe
- %APPDATA%\Microsoft\Windows\zUB8dknwC\zUB8dknwC.svr
- %APPDATA%\Microsoft\Windows\zUB8dknwC\zUB8dknwC.dat
- %APPDATA%\Microsoft\Windows\zUB8dknwC\zUB8dknwC.nfo
- %APPDATA%\Microsoft\Windows\zUB8dknwC\zUB8dknwC.svr
- 'ss####.moneyhome.biz':900
- 'wi####up.16-b.it':900
- 'h1###l3r.click':900
- 'c0######.is-not-certified.com':900
- 'dr#######cumentsandcustom.com':80
- 'localhost':1037
- 'www.dr##box.com':443
- 'k4#####4.publicvm.com':900
- http://dr#######cumentsandcustom.com/0ff1c3v4l1dKey2017.exe
- DNS ASK ss####.moneyhome.biz
- DNS ASK c0######.is-not-certified.com
- DNS ASK h1###l3r.click
- DNS ASK wi####up.16-b.it
- DNS ASK dr#######cumentsandcustom.com
- DNS ASK k4#####4.publicvm.com
- DNS ASK www.dr##box.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''