Техническая информация
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- C:\users\public\vbc.exe
- %TEMP%\nss4605.tmp\x369itfv9itih1g.dll
- C:\users\public\vbc.exe
- 'bi#.do':80
- 'wh#####lerbargains.com':80
- 'wo#####urcecloud.com':80
- 'be####ycarpethd.com':80
- 'de####ryourvote.com':80
- 'bu##ino.net':80
- '5b##j.com':80
- 'al######lleytimeshares.com':80
- 'cr#####nsbyjamie.com':80
- 'at####-kiano.com':80
- '85###0692.xyz':80
- 'me##.club':80
- '11##6.xyz':80
- http://www.sc####rworld.com/nsag/?K4##########################################################################################
- DNS ASK bi#.do
- DNS ASK me##.club
- DNS ASK 85###0692.xyz
- DNS ASK at####-kiano.com
- DNS ASK sc####rworld.com
- DNS ASK cr#####nsbyjamie.com
- DNS ASK al######lleytimeshares.com
- DNS ASK 11##6.xyz
- DNS ASK 5b##j.com
- DNS ASK de####ryourvote.com
- DNS ASK be####ycarpethd.com
- DNS ASK wo#####urcecloud.com
- DNS ASK wh#####lerbargains.com
- DNS ASK ch####dskeitaro.com
- DNS ASK st#######enkegfixryu.dns.army
- DNS ASK bu##ino.net
- DNS ASK no###one.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\colorcpl.exe'
- '%WINDIR%\syswow64\cmd.exe' del "C:\Users\Public\vbc.exe"