Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'yducevoj' = '"%WINDIR%\umejyliz.exe"'
- %WINDIR%\syswow64\explorer.exe
- %ALLUSERSPROFILE%\yjizuzobajiwaxeq\01000000
- %WINDIR%\umejyliz.exe
- %ALLUSERSPROFILE%\yjizuzobajiwaxeq\02000000
- %ALLUSERSPROFILE%\yjizuzobajiwaxeq\00000000
- DNS ASK yn######.kopeoxbbret.com
- DNS ASK an#####.kopeoxbbret.com
- DNS ASK iq#####.kopeoxbbret.com
- DNS ASK eh######ahu.kopeoxbbret.com
- DNS ASK jj####.kopeoxbbret.com
- DNS ASK ur######.kopeoxbbret.com
- DNS ASK cc######yno.kopeoxbbret.com
- DNS ASK yb###.#opeoxbbret.com
- '%WINDIR%\syswow64\explorer.exe'
- '<SYSTEM32>\vssvc.exe'