Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Rvchn' = '%HOMEPATH%\nhcvR.url'
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- C:\users\public\vbc.exe
- C:\users\public\libraries\temp
- %HOMEPATH%\links\rvchnkop.exe
- %HOMEPATH%\links\rvchn
- %HOMEPATH%\nhcvr.url
- %APPDATA%\sata\logs.iso
- C:\users\public\libraries\temp
- http://ti###rl.mobi/beAa
- http://ti###rl.mobi/?re###########
- http://19#.3.22.59/Acrbd64/document.doc
- http://19#.3.22.59/Acrbd64/Rsigned.exe
- DNS ASK ti###rl.mobi
- DNS ASK 1d#v.ws
- DNS ASK 4u####.#m.files.1drv.com
- DNS ASK 4s####e.ddns.net
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%ProgramFiles(x86)%\internet explorer\ieinstal.exe'