Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%WINDIR%\SysWow64\vnzyimac.exe" /shell'
- '%TEMP%\indexfpqwrxsp.exe'
- %WINDIR%\syswow64\explorer.exe
- iexplore.exe
- %TEMP%\indexfpqwrxsp.exe
- %WINDIR%\syswow64\vnzyimac.exe
- %TEMP%\indexfpqwrxsp.exe
- 'in####tionhub.de':80
- 'in####tionhub.de':443
- '78.##.248.147':80
- http://in####tionhub.de/wp-content/image.php?id############
- 'in####tionhub.de':443
- DNS ASK in####tionhub.de
- '%WINDIR%\syswow64\explorer.exe' "/executable"