Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\rhubbuuj.lnk
- <SYSTEM32>\tasks\opera scheduled autoupdate 536308134
- %APPDATA%\microsoft\windows\rhubbuuj\tvrsshrr.exe
- %APPDATA%\microsoft\windows\rhubbuuj\tvrsshrr.exe
- 'sh###owin.ru':443
- 'sh###ndpop.su':443
- http://www.ms###csi.com/ncsi.txt
- DNS ASK wi###shop.ug
- DNS ASK sh###owin.ru
- DNS ASK sh###ndpop.su