Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\tjraudjg.lnk
- <SYSTEM32>\tasks\opera scheduled autoupdate 1161675819
- %APPDATA%\microsoft\windows\tjraudjg\retvirur.exe
- %APPDATA%\microsoft\windows\tjraudjg\retvirur.exe
- 'io###8dudi.xyz':80
- http://www.ms###csi.com/ncsi.txt
- http://li####.adygeya.su/
- DNS ASK mi###aoin.info
- DNS ASK li####.adygeya.su
- DNS ASK io#####i.mangyshlak.su
- DNS ASK mi###diowi.xyz
- DNS ASK io###8dudi.xyz