Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Firefox' = 'C:\Bucks.exe'
- %TEMP%\{4esard0-9169-4c0f-a6cbbooss11518e}\{4esard0-9169-4c0f-a6cbbooss11518e}.exe
- %TEMP%\{4esard0-9169-4c0f-a6cbbooss11518e}\keygen.exe
- C:\bucks.exe
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012022051320220514\index.dat
- C:\bucks.exe
- 'b4#####7.linkbucks.com':80
- 'e6#####e.linkbucks.com':80
- DNS ASK e9#####8.linkbucks.com
- DNS ASK b4#####7.linkbucks.com
- DNS ASK 76#####8.linkbucks.com
- DNS ASK e6#####e.linkbucks.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\{4esard0-9169-4c0f-a6cbbooss11518e}\keygen.exe'
- '%TEMP%\{4esard0-9169-4c0f-a6cbbooss11518e}\{4esard0-9169-4c0f-a6cbbooss11518e}.exe'
- 'C:\bucks.exe'