Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%APPDATA%\vfbu.exe'
- %WINDIR%\Explorer.EXE
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'RegMonClass' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- %APPDATA%\vfbu.exe
- %TEMP%\B42CE9E6.TMP
- %APPDATA%\vfbu.exe
- DNS ASK up####windows.net
- DNS ASK ʔP#�
- DNS ASK _�##��
- DNS ASK li####dates2000.com
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Progman' WindowName: ''