Техническая информация
- '' (загружен из сети Интернет)
- '%APPDATA%\odinakazxc682.exe'
- %WINDIR%\explorer.exe
- odinakazxc682.exe
- %APPDATA%\odinakazxc682.exe
- %APPDATA%\odinakazxc682.exe
- 'eu###das.com':80
- 'wh##fxj.com':80
- 're###rpro.com':80
- 'sh###2ship.com':80
- 'ki####nful-dg.com':80
- 'eb###folly.com':80
- 'sc####physician.com':80
- 'ph###astery.com':80
- '4h###its.com':80
- http://www.wa#####wearafrica.com/9t6k/?y4############################################################################################
- http://www.bl#####lturewriters.com/9t6k/?y4############################################################################################
- DNS ASK fa###cheo.tk
- DNS ASK eu###das.com
- DNS ASK wh##fxj.com
- DNS ASK re###rpro.com
- DNS ASK sh###2ship.com
- DNS ASK aa###nline.com
- DNS ASK ga###etsl.com
- DNS ASK ki####nful-dg.com
- DNS ASK eb###folly.com
- DNS ASK sc####physician.com
- DNS ASK wa#####wearafrica.com
- DNS ASK bl#####lturewriters.com
- DNS ASK am###tur.com
- DNS ASK ph###astery.com
- DNS ASK cp###ivera.com
- DNS ASK 4h###its.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\wininit.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%APPDATA%\odinakazxc682.exe"