Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{f92B23AB-rpqb-iVaU-sNOU-0000F87A469H}] 'StubPath' = '%APPDATA%\A4btIk\9xaRBm.exe'
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\fonts\runqiu.ttf
- %WINDIR%\fonts\rqid.ttf
- %APPDATA%\a4btik\9xarbm.exe
- %APPDATA%\a4btik\liveudhelper.dll
- %WINDIR%\fonts\hanqiusheng.ttf
- DNS ASK j.##dz.win
- '%WINDIR%\syswow64\svchost.exe'