Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'dcxsagrhfojcrcedw' = '<SYSTEM32>\regsvr32.exe /s "%TEMP%\aiilibavsxgwwoy.DLL"'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'dcxsagrhfojcrcedw' = '<SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\aiilibavsxgwwoy.dll"'
- %TEMP%\nshc10e.tmp
- %TEMP%\nsxc11f.tmp\system.dll
- %TEMP%\aiilibavsxgwwoy.dll
- %WINDIR%\syswow64\rhchrwqsnr.exe
- %TEMP%\cv4ce27.tmp
- %TEMP%\cv4ce27.tmp
- %TEMP%\nsxc11f.tmp\system.dll
- %TEMP%\aiilibavsxgwwoy.dll в %WINDIR%\syswow64\aiilibavsxgwwoy.dll
- 'cp##ky.biz':80
- http://cp##ky.biz/bc/nsi_install.php?in###########################################################################
- http://cp##ky.biz/js/parking.2.94.0.js
- http://cp##ky.biz/bc/123kah.php
- DNS ASK cp##ky.biz
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\regsvr32.exe' /s "<SYSTEM32>\aiilibavsxgwwoy.dll"