Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'F4845319' = '%APPDATA%\F4845319\bin.exe'
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %HOMEPATH%\desktop\parnas_01.jpeg
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\13.jpg
- %HOMEPATH%\desktop\pushkin.jpg
- %HOMEPATH%\desktop\210252809.jpeg
- %HOMEPATH%\desktop\region-north-karelia.jpg
- %APPDATA%\f4845319\bin.exe
- 'yx####eugmmj.com':80
- 'ln####vvceon.com':80
- http://yx####eugmmj.com/in0odrfqwbio0sa/
- http://ln####vvceon.com/in0odrfqwbio0sa/
- DNS ASK google.com
- DNS ASK in####rtojertoq.cc
- DNS ASK yx####eugmmj.com
- DNS ASK ln####vvceon.com
- '%WINDIR%\syswow64\winver.exe'