Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vttbaelarvir' = '%ALLUSERSPROFILE%\Hithviwia\trbgertrnion.exe'
- '%ALLUSERSPROFILE%\hdrisair\dihakhvartik.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1500
- %ALLUSERSPROFILE%\hdrisair\dihakhvartik.exe
- %HOMEPATH%\mdtmedia\powerpoint.pptx
- %HOMEPATH%\mdtmedia\~$powerpoint.pptx
- %TEMP%\490591.cvr
- %APPDATA%\microsoft\windows\templates\data.zip
- %APPDATA%\Microsoft\windows\templates\wia08
- %APPDATA%\Microsoft\windows\templates\wia07
- %ALLUSERSPROFILE%\hithviwia\trbgertrnion.zip
- %ProgramFiles%\hithvi~1\trbgertrnion.exe
- %APPDATA%\microsoft\windows\templates\data.zip
- %ALLUSERSPROFILE%\hithviwia\trbgertrnion.zip
- '16#.#60.166.80':12214
- '16#.#60.166.80':8868
- '16#.#60.166.80':8868
- '%ALLUSERSPROFILE%\hdrisair\dihakhvartik.exe' ' (со скрытым окном)