Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\IhGXURXJVbCK.lnk
- '<SYSTEM32>\wscript.exe'
- '%APPDATA%\BdRC.exe' "%APPDATA%\BdRCU.au3"
- <SYSTEM32>\wscript.exe
- %APPDATA%\BdRC.exe
- %APPDATA%\BdRCU.au3
- %TEMP%\aut1.tmp
- %TEMP%\qtirpgd
- %HOMEPATH%\ck0g0BbX8AMgaZ9G\BdRCU.au3
- %HOMEPATH%\ck0g0BbX8AMgaZ9G\BdRC.exe
- %TEMP%\qtirpgd
- %TEMP%\aut1.tmp
- %APPDATA%\BdRC.exe в %HOMEPATH%\ck0g0BbX8AMgaZ9G\BdRC.exe
- %APPDATA%\BdRCU.au3 в %HOMEPATH%\ck0g0BbX8AMgaZ9G\BdRCU.au3
- 'mr####zy.ddns.net':4445
- DNS ASK mr####zy.ddns.net
- ClassName: 'Shell_TrayWnd' WindowName: ''