Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ewfwfw' = '%PROGRAMDATA%\weegfw.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ewfwfw' = '%PROGRAMDATA%\weegfw.exe'
- weegfw.exe
- %PROGRAMDATA%\weegfw.exe
- %PROGRAMDATA%\weegfw.exe
- http://www.ip###cation.com/
- DNS ASK fi##help.us
- DNS ASK ip###cation.com
- '%PROGRAMDATA%\weegfw.exe'