Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdater' = '"%APPDATA%\ahsleyhdnq789832.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\ahsleyhdnq789832.exe
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowsupdater.lnk
- '' (загружен из сети Интернет)
- '%APPDATA%\ahsleyhdnq789832.exe'
- ahsleyhdnq789832.exe
- %APPDATA%\ahsleyhdnq789832.exe
- %TEMP%\ahsleyhdnq789832.exe
- %LOCALAPPDATA%\get_cliboard_address\ahsleyhdnq789832.exe_url_pxhnaxnvjc1321m5i0ujwlrli1lnfado\1.0.0.0\xdelrcyi.newcfg
- %LOCALAPPDATA%\get_cliboard_address\ahsleyhdnq789832.exe_url_pxhnaxnvjc1321m5i0ujwlrli1lnfado\1.0.0.0\xdelrcyi.newcfg в %LOCALAPPDATA%\get_cliboard_address\ahsleyhdnq789832.exe_url_pxhnaxnvjc1321m5i0ujwlrli1lnfado\1.0.0.0\user.config
- 'lg##v.tk':80
- http://lg##v.tk/ashleyzx.exe
- DNS ASK lg##v.tk
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding