Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'TGBHQY' = '%TEMP%\yUaEXeUM.exe'
- %TEMP%\EGTYyPunQ.exe -h 1888
- %TEMP%\yUaEXeUM.exe -x
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\contact[1].htm
- %TEMP%\EGTYyPunQ.exe
- %TEMP%\yUaEXeUM.exe
- %TEMP%\EGTYyPunQ.exe
- '18#.#26.79.80':80
- ClassName: 'Indicator' WindowName: ''