Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'bluch' = '%ProgramFiles(x86)%\bluch\bluchup.exe'
- %TEMP%\nst756e.tmp
- %TEMP%\nsy758e.tmp\iekill.dll
- %TEMP%\nsy758e.tmp\killprocdll.dll
- %ProgramFiles(x86)%\bluch\bluch.dll
- %ProgramFiles(x86)%\bluch\bluchup.exe
- %ProgramFiles(x86)%\bluch\domainrefer.ini
- %ProgramFiles(x86)%\bluch\keycode.ini
- %ProgramFiles(x86)%\bluch\uninstall.exe
- %TEMP%\nsy758e.tmp\dllwebcount.dll
- %TEMP%\nsy758e.tmp\selfdelete.dll
- C:\delus.bat
- %TEMP%\nsy758e.tmp\dllwebcount.dll
- %TEMP%\nsy758e.tmp\iekill.dll
- %TEMP%\nsy758e.tmp\killprocdll.dll
- %TEMP%\nsy758e.tmp\selfdelete.dll
- DNS ASK ib###chip.kr
- ClassName: 'IEFrame' WindowName: ''
- '%ProgramFiles(x86)%\bluch\bluchup.exe'
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat (со скрытым окном)