Техническая информация
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- C:\users\public\vbc.exe
- C:\users\public\vbc.exe
- '3.##.198.110':80
- 'mi#####ageexpert.com':80
- 'ma####aroagency.com':80
- 'zw#.xyz':80
- 'se###ragon.com':80
- 'cr#####christians.com':80
- 'pa#######mentpetphotography.com':80
- 'iq##.info':80
- 'ga####laocai.com':80
- 'my###ysaver.com':80
- 'so######mebuyerclass.com':80
- 'or####cdiscover.com':80
- http://www.cu####gsforum.com/wufn/?Pb##################################################################################
- DNS ASK mi#####ageexpert.com
- DNS ASK ma####aroagency.com
- DNS ASK zw#.xyz
- DNS ASK br###ive.com
- DNS ASK se###ragon.com
- DNS ASK cr#####christians.com
- DNS ASK pa#######mentpetphotography.com
- DNS ASK iq##.info
- DNS ASK ga####laocai.com
- DNS ASK my###ysaver.com
- DNS ASK so######mebuyerclass.com
- DNS ASK am###pped.com
- DNS ASK or####cdiscover.com
- DNS ASK hs#######actionsettlement.com
- DNS ASK cu####gsforum.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\cmd.exe' del "C:\Users\Public\vbc.exe"