Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'vcuhwpyv' = '"%WINDIR%\arepahux.exe"'
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nsf5a50.tmp\userinfo.dll
- %APPDATA%\www.yify-torrents.com.jpg
- %TEMP%\nsf5a50.tmp\ane.dll
- %ALLUSERSPROFILE%\idumewitynofyran\01000000
- %WINDIR%\arepahux.exe
- %ALLUSERSPROFILE%\idumewitynofyran\02000000
- %ALLUSERSPROFILE%\idumewitynofyran\00000000
- %TEMP%\nsf5a50.tmp\ane.dll
- %TEMP%\nsf5a50.tmp\userinfo.dll
- DNS ASK ah###raje.ru
- '%WINDIR%\syswow64\explorer.exe'