Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,"%LOCALAPPDATA%\Pic1fPBkmq\LOHejsSdpL.exe" -s'
- %TEMP%\java86.exe
- %LOCALAPPDATA%\pic1fpbkmq\lohejssdpl.exe
- %TEMP%\java.exe
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012021041220210413\index.dat
- %LOCALAPPDATA%\pic1fpbkmq\lohejssdpl.exe
- 'cd#.##scordapp.com':443
- 'di##ord.gg':443
- 'di##ord.com':443
- 'cd#.##scordapp.com':443
- 'di##ord.gg':443
- 'di##ord.com':443
- DNS ASK cd#.##scordapp.com
- DNS ASK di##ord.gg
- DNS ASK microsoft.com
- DNS ASK di##ord.com
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\java86.exe'
- '%TEMP%\java.exe'