Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\smkhcfvcwghh.lnk
- %WINDIR%\syswow64\wscript.exe
- %TEMP%\ixp000.tmp\ntcodf~1.exe
- %TEMP%\aut685.tmp
- %TEMP%\makvfnm
- %APPDATA%\izxb.exe
- %APPDATA%\izxbs.au3
- %HOMEPATH%\hfiafp1vwbwvgyni\izxb.exe
- %HOMEPATH%\hfiafp1vwbwvgyni\izxbs.au3
- %TEMP%\aut685.tmp
- %TEMP%\makvfnm
- %TEMP%\ixp000.tmp\ntcodf~1.exe
- %APPDATA%\izxbs.au3 в %HOMEPATH%\hfiafp1vwbwvgyni\izxbs.au3
- %APPDATA%\izxb.exe в %HOMEPATH%\hfiafp1vwbwvgyni\izxb.exe
- DNS ASK sa#####es1989.hopto.org
- '%TEMP%\ixp000.tmp\ntcodf~1.exe'
- '%APPDATA%\izxb.exe' "%APPDATA%\IZXBS.au3"
- '%WINDIR%\syswow64\wscript.exe'
- '%TEMP%\ixp000.tmp\ntcodf~1.exe' (со скрытым окном)