Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Afpske cagyca] 'Start' = '00000002'
- '%PROGRAM_FILES%\Rublgc yanyc\Kyaghqo.exe'
- '%WINDIR%\Temp\cmd.com'
- '%WINDIR%\Temp\xs.exe'
- '<SYSTEM32>\wscript.exe' "C:\9594.vbs"
- %PROGRAM_FILES%\Rublgc yanyc\Kyaghqo.exe
- C:\9594.vbs
- %WINDIR%\Temp\cmd.com
- %WINDIR%\Temp\xs.exe
- C:\9594.vbs
- %WINDIR%\Temp\xs.exe
- 's0#.##ntongtec.com':1233
- DNS ASK s0#.##ntongtec.com