Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Java' = '%LOCALAPPDATA%\Java\java.exe'
- %LOCALAPPDATA%\java\java.exe
- %TEMP%\tmp950e.tmp
- %TEMP%\tmpb318.tmp
- %TEMP%\49135d9e03167d844f93af9adc3f1a7f.dat
- %LOCALAPPDATA%\java\java.exe
- 'pa###.#reehosting.com':21
- 'pa###.#reehosting.com':35208
- 'pa###.#reehosting.com':35827
- 'pa###.#reehosting.com':35316
- 'ga####sproducts.com':80
- http://ga####sproducts.com/pws/PWS.bin
- 'pa###.#reehosting.com':21
- 'pa###.#reehosting.com':35208
- 'pa###.#reehosting.com':35827
- 'pa###.#reehosting.com':35316
- DNS ASK ip#.#elize.com
- DNS ASK pa###.#reehosting.com
- DNS ASK ga####sproducts.com
- '%LOCALAPPDATA%\java\java.exe'