Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Service' = '%WINDIR%\system\wuaucltd.exe'
- %WINDIR%\1hsaced0c.txt
- %WINDIR%\hsaced0c.txt
- %WINDIR%\1hsaced0c.txt
- %WINDIR%\hsaced0c.txt
- 'www.en######iadepaula.com.br':80
- 'www.te###.com.br':80
- '19#.#06.228.156':80
- www.en######iadepaula.com.br/fontes/9/dois.txt
- www.en######iadepaula.com.br/fontes/9/um.txt
- 19#.#06.228.156/1.php
- DNS ASK www.en######iadepaula.com.br
- DNS ASK www.te###.com.br
- ClassName: 'MS_WINHELP' WindowName: '(null)'