Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'GoogleInc' = '%WINDIR%\system\yffglgbb.vbs'
- %TEMP%\phpfb4f.tmp
- %TEMP%\phpfb7e.tmp
- %TEMP%\phpfb7f.tmp
- %WINDIR%\system\yffglgbb.vbs
- %WINDIR%\system\yffglgbb.exe
- %TEMP%\php19c7.tmp
- %TEMP%\php19e7.tmp
- %TEMP%\php19f7.tmp
- %WINDIR%\system\yffglgbb.vbs
- %WINDIR%\system\yffglgbb.vbs
- DNS ASK ka###oto.info
- DNS ASK be###pe.info
- DNS ASK st###gback.info
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\system\yffglgbb.vbs"
- '%WINDIR%\system\yffglgbb.exe'
- '%WINDIR%\syswow64\cmd.exe' /c reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v GoogleInc /t REG_SZ /d %WINDIR%\system\yffglgbb.vbs /f
- '%WINDIR%\syswow64\reg.exe' add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v GoogleInc /t REG_SZ /d %WINDIR%\system\yffglgbb.vbs /f
- '%WINDIR%\syswow64\cmd.exe' /c C:/Windows/system/yffglgbb.vbs
- '%WINDIR%\system\yffglgbb.exe' (со скрытым окном)