Техническая информация
- Средство контроля пользовательских учетных записей (UAC)
- '<SYSTEM32>\cmd.exe' /c pause
- '%TEMP%\xloxgygtwg.exe' -
- nod32.exe
- <Текущая директория>\flghissxsufsjvciobpvqrsc.hce
- %TEMP%\flghissxsufsjvciobpvqrsc.hce
- <Текущая директория>\wc_drop.exe
- %TEMP%\xloxgygtwg.exe
- %ProgramFiles%\flghissxsufsjvciobpvqrsc.hce
- <SYSTEM32>\flghissxsufsjvciobpvqrsc.hce
- %WINDIR%\flghissxsufsjvciobpvqrsc.hce
- <LS_APPDATA>\flghissxsufsjvciobpvqrsc.hce
- 'wh#####yipaddress.com':80
- 'wh#####yip.everdot.org':80
- 'www.wh###smyip.com':80
- 'any':80
- 'www.wh###smyip.ca':80
- 'www.wh###smyip.org':80
- http://wh#####yipaddress.com/
- http://wh#####yip.everdot.org/
- http://www.wh###smyip.com/
- http://we#r���� via any
- http://www.wh###smyip.ca/
- http://www.wh###smyip.org/
- DNS ASK wh#####yip.everdot.org
- DNS ASK www.wh###smyip.com
- DNS ASK wh#####yipaddress.com
- DNS ASK www.wh###smyip.ca
- DNS ASK www.wh###smyip.org