Техническая информация
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- C:\users\public\vbc.exe
- '18#.#22.57.252':80
- 'cd#.##scordapp.com':443
- 'wi###ashaw.com':80
- 'ca###rkc.com':80
- 'oc##.thawte.com':80
- 'da######fcourselondon.com':80
- 'ca###nter.com':80
- 'ar###ner.com':80
- 'kn####slunarius.com':80
- 'mi####nsport.com':80
- 'ex###emal.com':80
- 'dj####-fashion.com':80
- http://www.te###alktv.com/bsk9/?mr###############################################################################################
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- DNS ASK wi###ashaw.com
- DNS ASK ca###rkc.com
- DNS ASK oc##.thawte.com
- DNS ASK da######fcourselondon.com
- DNS ASK ca###nter.com
- DNS ASK lo#####likeabout.com
- DNS ASK na#####resourcesmgt.com
- DNS ASK ar###ner.com
- DNS ASK kn####slunarius.com
- DNS ASK mi####nsport.com
- DNS ASK te###alktv.com
- DNS ASK yo####dastouch.com
- DNS ASK ex###emal.com
- DNS ASK dj####-fashion.com
- DNS ASK sd###atong.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\dialer.exe'
- '%WINDIR%\syswow64\rundll32.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\SysWOW64\dialer.exe"