Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'zywnryvr' = '%APPDATA%\iradcb\ckaejhq.exe'
- '<SYSTEM32>\dllhost.exe' /Processid:{76F22F0F-D3C8-4238-A6D7-2AA43D7358FA}
- <SYSTEM32>\dllhost.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\DEB4756E3CB5DDB0C286F16EF609B0FF[1].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\01F2D1E2B5FCC0F85CF30B12687C4A83[1].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\8E539DB4A677C6DA5844EA046CCBAB95[1].htm
- %APPDATA%\iradcb\ckaejhq.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\0ABE2B6E710F3D248F3C11FABBB3506B[1].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\1A929BF2518684BFB8894F558C060EC4[1].htm
- 'so##kas.ru':80
- DNS ASK so##kas.ru