Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Cbmjuki' = '"%APPDATA%\Njvgm\Cbmjuki.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Aoev' = '"%APPDATA%\Nakgjel\Aoev.exe"'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] '‚k' = '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- %TEMP%\puzqnrwtetucuhi.exe
- %APPDATA%\njvgm\cbmjuki.exe
- %APPDATA%\install\host.exe
- %APPDATA%\nakgjel\aoev.exe
- '3.##.247.229':80
- 'localhost':3360
- http://3.##.247.229/t0/loader/uploads/Rpvmig_Ahzwgjuw.bmp
- http://3.##.247.229/dash/loader/uploads/uhi_Expysmzy.jpg
- '%TEMP%\puzqnrwtetucuhi.exe'
- '%APPDATA%\install\host.exe'
- '%WINDIR%\syswow64\cmd.exe' /c timeout 10' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c timeout 10
- '%WINDIR%\syswow64\timeout.exe' 10
- '%WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe'