Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'egyrlhah' = '"%WINDIR%\ezehezof.exe"'
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet
- '%WINDIR%\explorer.exe'
- %WINDIR%\explorer.exe
- %WINDIR%\ezehezof.exe
- %ALLUSERSPROFILE%\Application Data\exaxykederajugot\02000000
- %ALLUSERSPROFILE%\Application Data\exaxykederajugot\00000000
- %ALLUSERSPROFILE%\Application Data\exaxykederajugot\01000000
- %TEMP%\nsi2.tmp\UserInfo.dll
- %APPDATA%\05 A Pause.mp3
- %TEMP%\nsi2.tmp\abidance.dll
- %TEMP%\nsi2.tmp\UserInfo.dll
- %TEMP%\nsi2.tmp\abidance.dll
- 'gi###emydata.ru':443
- DNS ASK gi###emydata.ru