Техническая информация
- %APPDATA%\windows.lnk
- %WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe
- %TEMP%\dkaavjart
- %APPDATA%\windows.lnk
- %APPDATA%\vhsxguu\lpnmavq.exe
- %APPDATA%\gmwwbs\lcjrgq.exe
- %APPDATA%\microsoft\windows\9hgvnkaakzh\9hgvnkaakzh.nfo
- %APPDATA%\microsoft\windows\9hgvnkaakzh\9hgvnkaakzh.dat
- %APPDATA%\microsoft\windows\9hgvnkaakzh\9hgvnkaakzh.svr
- %APPDATA%\microsoft\windows\9hgvnkaakzh\9hgvnkaakzh.nfo
- %APPDATA%\microsoft\windows\9hgvnkaakzh\9hgvnkaakzh.dat
- %APPDATA%\microsoft\windows\9hgvnkaakzh\9hgvnkaakzh.svr
- %APPDATA%\microsoft\windows\9hgvnkaakzh\9hgvnkaakzh.svr
- %APPDATA%\windows.lnk
- 'dr##box.com':443
- 'ja#######ngsetts.ignorelist.com':996
- 'dr##box.com':443
- DNS ASK dr##box.com
- DNS ASK sp#######ctest.ciscofreak.com
- DNS ASK bu#######mpleointernacional.com
- DNS ASK s0###.##activedirectory.com
- DNS ASK is######y.cable-modem.org
- DNS ASK se######ssl.mymediapc.net
- DNS ASK ja#######ngsetts.ignorelist.com
- '%WINDIR%\syswow64\cmd.exe' /c del /q /f %temp%\*.lnk' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c start %temp%\KrKBfsZjT.exe' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe'
- '%WINDIR%\syswow64\cmd.exe' /c del /q /f %temp%\*.lnk
- '%WINDIR%\syswow64\cmd.exe' /c start %temp%\KrKBfsZjT.exe