Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'social' = '%HOMEPATH%\My Documents\ddabadfb\social.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'doriva' = '%HOMEPATH%\My Documents\ddabadfb\doriva.exe'
- ClassName: 'pediy06' WindowName: ''
- ClassName: 'GBDYLLO' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- %HOMEPATH%\My Documents\ddabadfb\imagens.zip
- 'cd########.dominiotemporario.com':80
- cd########.dominiotemporario.com/imagens.zip
- DNS ASK cd########.dominiotemporario.com
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Indicator' WindowName: ''