Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'USBSERV' = '%APPDATA%\usbdump.exe'
- %APPDATA%\rpcsrv.log
- %APPDATA%\usbdump.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\calc[1].exe
- '17#.#12.192.83':80
- 17#.#12.192.83/modules/docs/upload/calc.exe
- 17#.#12.192.83/modules/docs/index1.php?ve#################################
- ClassName: 'Indicator' WindowName: ''