Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'localemi' = '%HOMEPATH%\Application Data\localemi.exe'
- %HOMEPATH%\application data\localemi.exe
- %HOMEPATH%\application data\scrrun.dll
- %HOMEPATH%\application data\msinet.ocx
- %HOMEPATH%\application data\msvbvm60.dll
- %HOMEPATH%\application data\vb6ko.dll
- %TEMP%\nsvd2aa.tmp\selfdelete.dll
- C:\delus.bat
- %TEMP%\nsvd2aa.tmp\selfdelete.dll
- DNS ASK fp#.##oryfolder.com
- '%HOMEPATH%\application data\localemi.exe'
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat (со скрытым окном)