Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'BEDYRER' = '%HOMEPATH%\harmeligst\cranioplasty.vbs'
- '' (загружен из сети Интернет)
- '%APPDATA%\vbc.exe'
- cranioplasty.exe
- %APPDATA%\vbc.exe
- %HOMEPATH%\harmeligst\cranioplasty.exe
- %HOMEPATH%\harmeligst\cranioplasty.vbs
- http://13#.#80.163.57/svchost.exe
- http://21#.#38.205.164/Host_encrypted_F17BD4F.bin
- DNS ASK el#####king444.ddns.net
- '%HOMEPATH%\harmeligst\cranioplasty.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding