Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '%LOCALAPPDATA%\hip.exe'
- %WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe
- %APPDATA%\new text document.txt
- %LOCALAPPDATA%\hip.exe
- %WINDIR%\microsoft.net\framework\v2.0.50727\.identifier
- %WINDIR%\microsoft.net\framework\v2.0.50727\.identifier
- 'tr######min.moneyhome.biz':3360
- DNS ASK tr######min.moneyhome.biz
- '%LOCALAPPDATA%\hip.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe'