Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'iqmvfbk' = '%APPDATA%\vfoktpyiemvrb\wgplueajfoxtdm.exe "%TEMP%\avxyq.exe" %HOMEPATH%\AppData�'
- avxyq.exe
- %TEMP%\nsi5419.tmp
- %TEMP%\narwbaekgvw.wt
- %TEMP%\efkmzemi.oij
- %TEMP%\avxyq.exe
- %APPDATA%\vfoktpyiemvrb\wgplueajfoxtdm.exe
- DNS ASK bl#####ots7.duckdns.org
- '%TEMP%\avxyq.exe' %TEMP%\efkmzemi.oij
- '%TEMP%\avxyq.exe'