Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\vFWviyGnuHBe.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\vFWviyGnuHBe.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\YozuDOJONelX\vFWviyGnuHBe.dll"'
- 'vFWviyGnuHBe.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\YozuDOJONelX\vFWviyGnuHBe.dll"
- '<SYSTEM32>\regsvr32.exe' ..\xwnlm.ocx
- %HOMEPATH%\xwnlm.ocx
- <Текущая директория>\b6d51000
- %HOMEPATH%\xwnlm.ocx в <SYSTEM32>\yozudojonelx\vfwviygnuhbe.dll
- <PATH_SAMPLE>.xls
- 'mc####licschool.com':80
- http://mc####licschool.com/Achievements/FbgG5Xk/
- DNS ASK mc####licschool.com
- '<SYSTEM32>\regsvr32.exe' ..\xwnlm.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\YozuDOJONelX\vFWviyGnuHBe.dll"