Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\vdbegiiuusnd.lnk
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %TEMP%\ixp000.tmp\whjdedmans.exe
- %TEMP%\aut314c.tmp
- %TEMP%\ixp000.tmp\cbgd.exe
- %TEMP%\aut3218.tmp
- %TEMP%\ixp000.tmp\fpoka
- %APPDATA%\cbgd.exe
- %APPDATA%\fpoka
- %TEMP%\xx--xx--xx.txt
- %APPDATA%\cglogs.dat
- %TEMP%\xxx.xxx
- %TEMP%\uuu.uuu
- %HOMEPATH%\bagcjb46apnhamer\cbgd.exe
- %HOMEPATH%\bagcjb46apnhamer\fpoka
- %APPDATA%\cglogs.dat
- %TEMP%\aut314c.tmp
- %TEMP%\aut3218.tmp
- %TEMP%\ixp000.tmp\whjdedmans.exe
- %TEMP%\ixp000.tmp\cbgd.exe
- %TEMP%\ixp000.tmp\fpoka
- %TEMP%\xx--xx--xx.txt
- %TEMP%\uuu.uuu
- %TEMP%\xxx.xxx
- %APPDATA%\fpoka в %HOMEPATH%\bagcjb46apnhamer\fpoka
- %APPDATA%\cbgd.exe в %HOMEPATH%\bagcjb46apnhamer\cbgd.exe
- %TEMP%\uuu.uuu
- %TEMP%\xxx.xxx
- DNS ASK gu####ria.dynu.com
- DNS ASK em####r.hopto.org
- '%TEMP%\ixp000.tmp\whjdedmans.exe'
- '%APPDATA%\cbgd.exe' "%APPDATA%\fPOKa"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'
- '%ProgramFiles(x86)%\opera\launcher.exe'
- '%TEMP%\ixp000.tmp\whjdedmans.exe' (со скрытым окном)