Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\hysxuqqpawfj.lnk
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %TEMP%\ixp000.tmp\qswewsigbg.exe
- %TEMP%\aut5003.tmp
- %TEMP%\eyymvfe
- %APPDATA%\fbgj.exe
- %APPDATA%\bdaen.au3
- %HOMEPATH%\bcrs1hoig0csspmz\bdaen.au3
- %HOMEPATH%\bcrs1hoig0csspmz\fbgj.exe
- %TEMP%\aut5003.tmp
- %TEMP%\eyymvfe
- %TEMP%\ixp000.tmp\qswewsigbg.exe
- %APPDATA%\bdaen.au3 в %HOMEPATH%\bcrs1hoig0csspmz\bdaen.au3
- %APPDATA%\fbgj.exe в %HOMEPATH%\bcrs1hoig0csspmz\fbgj.exe
- '34.##9.100.209':443
- '%TEMP%\ixp000.tmp\qswewsigbg.exe'
- '%APPDATA%\fbgj.exe' "%APPDATA%\bDAeN.au3"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'
- '%TEMP%\ixp000.tmp\qswewsigbg.exe' (со скрытым окном)