Техническая информация
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- C:\users\public\vbc.exe
- %TEMP%\nsxf47c.tmp\0ps12v89.dll
- C:\users\public\vbc.exe
- 'ow.ly':80
- 'al######lleytimeshares.com':80
- 'ex####erthecity.com':80
- 'ha####hawatmi.com':80
- 'si##zim.com':80
- 'ic##olo.com':80
- '85###0692.xyz':80
- 'in####healer.com':80
- 'wo#####urcecloud.com':80
- '5b##j.com':80
- http://www.wi###eel.com/nsag/?Nr#############################################################################################
- DNS ASK ow.ly
- DNS ASK al#######dykegfixtal.dns.army
- DNS ASK al######lleytimeshares.com
- DNS ASK ex####erthecity.com
- DNS ASK ha####hawatmi.com
- DNS ASK si##zim.com
- DNS ASK ic##olo.com
- DNS ASK wi###eel.com
- DNS ASK 85###0692.xyz
- DNS ASK in####healer.com
- DNS ASK wo#####urcecloud.com
- DNS ASK 5b##j.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\colorcpl.exe'
- '%WINDIR%\syswow64\cmd.exe' del "C:\Users\Public\vbc.exe"