Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'dlf_00000400' = '<SYSTEM32>\Vcdlf.exe /c'
- %TEMP%\FDL1.tmp
- <SYSTEM32>\Vcdlf.exe
- %WINDIR%\dlforcer.ini
- '19#.#09.72.200':9469
- '19#.#09.94.160':9469
- 'ge####lounge.com':80
- ge####lounge.com/download/geisha.exe
- DNS ASK ge####lounge.com
- ClassName: 'Shell_TrayWnd' WindowName: ''