Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Update' = '%TEMP%\skyp\Microsoft Update.lnk'
- 'C:\sswr\Rar.exe' e -p16509408 nvra.rar
- '<SYSTEM32>\wscript.exe' "C:\sswr\wcdvnb.vbs"
- '%TEMP%\XOUPLG.exe'
- '<SYSTEM32>\wscript.exe' "C:\sswr\jbxqo.vbs"
- '<SYSTEM32>\cmd.exe' /c ""C:\sswr\elkkck.bat" "
- '<SYSTEM32>\netsh.exe' advfirewall set allprofiles state off
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %TEMP%\DPQRXY.jpg
- '<SYSTEM32>\cmd.exe' /c ""C:\sswr\brqaz.bat" "
- C:\sswr\vp8encoder.dll
- C:\sswr\wcdvnb.vbs
- C:\sswr\nvra.rar
- C:\sswr\jbxqo.vbs
- C:\sswr\elkkck.bat
- C:\sswr\orkva.reg
- C:\sswr\omzmyjo.exe
- C:\sswr\cqjovddnan.exe
- C:\sswr\brqaz.bat
- %TEMP%\aut2.tmp
- %TEMP%\XOUPLG.exe
- %TEMP%\aut1.tmp
- %TEMP%\ztudxky
- C:\sswr\run.vbs
- C:\sswr\Rar.exe
- %TEMP%\aut3.tmp
- %TEMP%\DPQRXY.jpg
- %TEMP%\aut3.tmp
- C:\sswr\jbxqo.vbs
- C:\sswr\nvra.rar
- %TEMP%\aut1.tmp
- %TEMP%\ztudxky
- %TEMP%\aut2.tmp
- 'ba####file.ddns.net':443
- DNS ASK ba####file.ddns.net
- ClassName: 'EDIT' WindowName: ''