Техническая информация
- 'C:\users\public\vbc.exe'
- vbc.exe
- [<HKCU>\Software\LinasFTP\Site Manager]
- [<HKCU>\Software\FlashPeak\BlazeFtp\Settings]
- [<HKCU>\Software\Ghisler\Total Commander]
- [<HKCU>\Software\mIRC]
- [<HKCU>\Software\Far\Plugins\FTP\Hosts]
- [<HKCU>\Software\Far2\Plugins\FTP\Hosts]
- [<HKCU>\Software\VanDyke\SecureFX]
- [<HKLM>\Software\WOW6432Node\NCH Software\Fling\Accounts]
- [<HKCU>\Software\NCH Software\Fling\Accounts]
- [<HKLM>\Software\WOW6432Node\NCH Software\ClassicFTP\FTPAccounts]
- [<HKCU>\Software\NCH Software\ClassicFTP\FTPAccounts]
- [<HKCU>\Software\SimonTatham\PuTTY\Sessions]
- [<HKLM>\Software\WOW6432Node\SimonTatham\PuTTY\Sessions]
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\thunderbird\profiles.ini
- C:\users\public\vbc.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\vbc.exe.log
- http://10#.#55.80.77/https/.smss.exe
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%CommonProgramFiles(x86)%\microsoft shared\equation\eqnedt32.exe' -Embedding