Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'yiCrfu' = 'C:\yiCrfuyiCrfu\yiCrfu.vbs'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe'
- '%APPDATA%\y4ody\k5ki7.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
- C:\yiCrfuyiCrfu\x
- C:\yiCrfuyiCrfu\yiCrfu.exe
- %APPDATA%\23EF5514-3059-436F-A4A7-4CEFAAB20EB1\run.dat
- C:\yiCrfuyiCrfu\yiCrfu.vbs
- %APPDATA%\y4ody\k5ki7.exe
- %APPDATA%\y4ody\x
- %APPDATA%\yiCrfu
- 'www.dr##box.com':443
- 'localhost':1039
- '18#.#2.221.11':1602
- DNS ASK www.dr##box.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''