Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Integrated Driver' = '%APPDATA%\Identities\wlnlog.exe'
- %TEMP%\uwcyeocunvshxf\checker.exe -c "%TEMP%\uwcyeocunvshxf\system"
- %APPDATA%\Identities\wlnlog.exe
- %TEMP%\t6sp.exe
- %TEMP%\uwcyeocunvshxf\libpdcurses.dll
- %TEMP%\uwcyeocunvshxf\libusb-1.0.dll
- %TEMP%\uwcyeocunvshxf\pdcurses.dll
- %TEMP%\uwcyeocunvshxf\libeay32.dll
- %TEMP%\uwcyeocunvshxf\libidn-11.dll
- %TEMP%\uwcyeocunvshxf\libjansson-4.dll
- %TEMP%\uwcyeocunvshxf\phatk121016.cl
- %TEMP%\uwcyeocunvshxf\ssleay32.dll
- %TEMP%\uwcyeocunvshxf\zlib1.dll
- %TEMP%\uwcyeocunvshxf\zzBPAvira.junk
- %TEMP%\uwcyeocunvshxf\poclbm121016.cl
- %TEMP%\uwcyeocunvshxf\pthreadGC2.dll
- %TEMP%\uwcyeocunvshxf\scrypt121016.cl
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\raw[1].php
- %APPDATA%\Identities\IMG_37153486_1256458.jpg
- %TEMP%\uwcyeocunvshxf\system
- %TEMP%\t6sp.exe
- %APPDATA%\Identities\wlnlog.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\raw[1].php
- %TEMP%\uwcyeocunvshxf\checker.exe
- %TEMP%\uwcyeocunvshxf\libblkmaker_jansson-0.1-0.dll
- %TEMP%\uwcyeocunvshxf\libcurl-4.dll
- %TEMP%\uwcyeocunvshxf\libcurl.dll
- %TEMP%\uwcyeocunvshxf\diablo121016.cl
- %TEMP%\uwcyeocunvshxf\diakgcn121016.cl
- %TEMP%\uwcyeocunvshxf\libblkmaker-0.1-0.dll
- 'pa###bin.com':80
- pa###bin.com/raw.php?i=########
- DNS ASK mi####.eligius.st
- DNS ASK po##.50btc.com
- DNS ASK pa###bin.com
- ClassName: 'Indicator' WindowName: ''