Техническая информация
- [HKCU\Software\Microsoft\Windows\Currentversion\Run] 'Ymobw' = '%APPDATA%\Cyum\ereh.exe'
- %WINDIR%\syswow64\cmd.exe
- <SYSTEM32>\conhost.exe
- iexplore.exe
- firefox.exe
- winmail.exe
- [HKLM\SOFTWARE\Wow6432Node\FlashFXP\3]
- [HKCU\SOFTWARE\Ghisler\Total Commander]
- [HKCU\SOFTWARE\Far\Plugins\ftp\hosts]
- [HKCU\SOFTWARE\Far2\Plugins\ftp\hosts]
- [HKCU\SOFTWARE\martin prikryl\winscp 2\sessions]
- [HKLM\SOFTWARE\Wow6432Node\martin prikryl\winscp 2\sessions]
- [HKCU\SOFTWARE\ftpware\coreftp\sites]
- [HKCU\Software\Microsoft\Windows Mail]
- [HKCU\Software\Microsoft\Windows Live Mail]
- %APPDATA%\cyum\ereh.exe
- %APPDATA%\etbe\haqo.ohl
- %TEMP%\tmpa9b980ab.bat
- %TEMP%\ppcrlui_2864_2
- %TEMP%\ppcrlui_2864_2
- %APPDATA%\etbe\haqo.ohl в %APPDATA%\etbe\haqo.tmp
- DNS ASK vu####hoto10.com
- DNS ASK vu####hoto20.com
- ClassName: 'OutlookExpressHiddenWindow' WindowName: ''
- '%APPDATA%\cyum\ereh.exe'
- '%ProgramFiles%\windows mail\winmail.exe' -Embedding
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\tmpa9b980ab.bat" (со скрытым окном)