Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Project1' = '%APPDATA%\qtjhtf\Project1.exe'
- '%TEMP%\Svchost.exe'
- '%TEMP%\RarSFX0\DMRChJ.exe' "qtjhTf"
- %APPDATA%\qtjhtf\ebbNFc.txt
- %APPDATA%\qtjhtf\qtjhTf
- %TEMP%\Svchost.exe
- %APPDATA%\qtjhtf\DMRChJ.exe
- %APPDATA%\qtjhtf\1.txt
- %APPDATA%\qtjhtf\2.txt
- %APPDATA%\qtjhtf\skype.exe
- %APPDATA%\qtjhtf\Project1.exe
- %TEMP%\RarSFX0\DMRChJ.exe
- %TEMP%\RarSFX0\rJtsqy.exe
- %TEMP%\RarSFX0\qtjhTf
- %TEMP%\RarSFX0\ebbNFc.txt
- %TEMP%\rJtsqy.exe
- %TEMP%\qtjhTf
- %TEMP%\ebbNFc.txt
- %TEMP%\DMRChJ.exe
- %TEMP%\RarSFX0\qtjhTf
- %TEMP%\RarSFX0\rJtsqy.exe
- %TEMP%\RarSFX0\DMRChJ.exe
- %TEMP%\RarSFX0\ebbNFc.txt
- 'iu#####azy.blogdns.com':5454
- DNS ASK iu#####azy.blogdns.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''