Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'svchost' = '%APPDATA%\servcrypt.exe'
- %APPDATA%\servcrypt.exe
- %APPDATA%\svchost.exe
- %APPDATA%\mnnayceeo.exe
- %WINDIR%\syswow64\install\server.exe
- %TEMP%\user2.txt
- %APPDATA%\userlog.dat
- %TEMP%\user7
- %TEMP%\user8
- %APPDATA%\userlog.dat
- %TEMP%\user2.txt
- %TEMP%\user8
- %TEMP%\user7
- %TEMP%\user8
- %TEMP%\user7
- DNS ASK sh####34.no-ip.biz
- '%APPDATA%\svchost.exe'
- '%APPDATA%\mnnayceeo.exe'
- '%WINDIR%\syswow64\install\server.exe'