Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'vlc' = '"%APPDATA%\Microsoft\Windows\Start Menu\Programs\VideoLAN\vlc.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'e6384711491713d29bc63fc5eeb5ba4f' = '%ALLUSERSPROFILE%\Important.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %APPDATA%\microsoft\windows\start menu\programs\videolan\vlc.exe
- %ALLUSERSPROFILE%\important.exe
- %ALLUSERSPROFILE%\apohpjr_11_10_17_25_1.jpg
- %ALLUSERSPROFILE%\apohpjr_11_10_17_25_1.jpg
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe в %APPDATA%\regasm.exe
- 'sh####ongtinh.com':80
- http://sh####ongtinh.com/keybase/post.php?ty######################################################################################################
- http://sh####ongtinh.com/keybase/image/upload.php
- DNS ASK sh####ongtinh.com
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'