Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'fd9edd8ad33740ccb68ac1c6baa23a09' = '%APPDATA%\wxrvlx\wxrvlx.exe'
- [<HKCU>\Software\Martin Prikryl\WinSCP 2\Sessions]
- [<HKCU>\Software\Beyluxe Messenger]
- [<HKCU>\Software\IMVU]
- [<HKCU>\Software\Paltalk]
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\wxrvlx\wxrvlx.exe
- %APPDATA%\zdq
- %TEMP%\tmp3848.tmp
- %TEMP%\tmp3878.tmp
- http://bo#.####ismyipaddress.com/
- DNS ASK bo#.####ismyipaddress.com
- '%APPDATA%\wxrvlx\wxrvlx.exe'