Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'EBYQS' = '<SYSTEM32>\winrsj.exe'
- '<SYSTEM32>\winrsj.exe'
- '<SYSTEM32>\wermgr.exe' -queuereporting
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\dw20.exe' -x -s 500
- '<SYSTEM32>\conhost.exe'
- %TEMP%\~unins8136.bat
- <SYSTEM32>\winrsj.exe
- <SYSTEM32>\winrsj.exe
- '11#.#.231.200':80
- 11#.#.231.200/site/scripts/all.html
- DNS ASK in###ave.com