Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'C2Zdxvm5pt' = '%ALLUSERSPROFILE%\ddeaepscann\8CoSd6BZxC_69lYe\C2Zdxvm5pt.exe'
- %ALLUSERSPROFILE%\ddeaepscann\8cosd6bzxc_69lye\c2zdxvm5pt.exe
- %ALLUSERSPROFILE%\ddeaepscann\8cosd6bzxc_69lye\msvcp100.dll
- %ALLUSERSPROFILE%\ddeaepscann\8cosd6bzxc_69lye\msvcr100.dll
- %ALLUSERSPROFILE%\ddeaepscann\8cosd6bzxc_69lye\crclient.dll
- %ALLUSERSPROFILE%\ddeaepscann\8cosd6bzxc_69lye\c2zdxvm5pt.txt
- %LOCALAPPDATA%\178bfbff000306e4
- %ALLUSERSPROFILE%\ddeaepscann\8cosd6bzxc_69lye\key
- '15#.#40.106.253':8080
- '15#.#40.106.253':12345
- http://15#.###.106.253:8080/9x.dll via 15#.#40.106.253
- '15#.#40.106.253':12345
- ClassName: '' WindowName: ''
- '%ALLUSERSPROFILE%\ddeaepscann\8cosd6bzxc_69lye\c2zdxvm5pt.exe'
- '<Полный путь к файлу>' 47043E045804540476046B046304760465046904400465047004650458046004600461046504610474047704670465046A046A0458043C0447046B0457046004320446045E047C0447045B0432043D0468045D0461045804470436045E0460047... (со скрытым окном)