Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'd3dx32' = '%APPDATA%\minceraft\System.lnk'
- %APPDATA%\microsoft\windows\start menu\programs\startup\system.lnk
- %APPDATA%\microsoft\windows\start menu\programs\startup\bkphst32.lnk
- %APPDATA%\microsoft\windows\start menu\programs\startup\winlog.lnk
- %TEMP%\cdgh.exe
- %TEMP%\xxmbk.exe
- %APPDATA%\ssjk.exe
- %APPDATA%\minceraft\msg.vbs
- %APPDATA%\minceraft\mos
- %APPDATA%\minceraft\6xcvketgnlpql8bot6fw9obygudy4i.bat
- %APPDATA%\minceraft\vmcheck32.dll
- %APPDATA%\minceraft\fontreview.exe
- %APPDATA%\minceraft\system.vbe
- %APPDATA%\minceraft\system.lnk
- %HOMEPATH%\pictures\bkphst32.exe
- %HOMEPATH%\pictures\bkphst32.lnk
- %HOMEPATH%\pictures\vmcheck32.dll
- %APPDATA%\minceraft\winlog.lnk
- %TEMP%\xxmbk.exe
- %APPDATA%\ssjk.exe
- DNS ASK ko###off.xyz
- DNS ASK ip##fo.io
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\xxmbk.exe' -s -pfsdgsdfvsdzcxfsDC
- '%APPDATA%\ssjk.exe'
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\minceraft\System.vbe"
- '%TEMP%\cdgh.exe'
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\minceraft\msg.vbs"
- '%APPDATA%\minceraft\fontreview.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\minceraft\6xcVKEtGNlpql8bot6FW9obyGuDy4I.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\minceraft\6xcVKEtGNlpql8bot6FW9obyGuDy4I.bat" "