Техническая информация
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %APPDATA%\3b49b.xsl
- %TEMP%\1199320.cvr
- %WINDIR%\temp\widyc.dll
- 'au###laser.com':443
- 'fu###npe.org':443
- 'le#####fgooddeeds.com':80
- http://le#####fgooddeeds.com/wp-includes/js/tinymce/themes/inlite/HQfVfwoKlw4Qb.php
- 'au###laser.com':443
- 'fu###npe.org':443
- DNS ASK ne###a-store.ir
- DNS ASK au###laser.com
- DNS ASK ba####otmind.org
- DNS ASK we###nd.org.ng
- DNS ASK fu###npe.org
- DNS ASK le#####fgooddeeds.com
- ClassName: 'conSolEWiNDOWCLass' WindowName: ''
- '<SYSTEM32>\wbem\wmic.exe' ' (со скрытым окном)
- '<SYSTEM32>\wbem\wmic.exe'
- '<SYSTEM32>\rundll32.exe' C:/Windows/Temp//widyc.dll DllRegisterServer