Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\ycflvtoeegil.lnk
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %WINDIR%\syswow64\notepad.exe
- %TEMP%\ixp000.tmp\jqfawc~1.exe
- %TEMP%\autce56.tmp
- %TEMP%\ixp000.tmp\wuzr1
- %TEMP%\ixp000.tmp\wuzr.exe
- %TEMP%\autd02b.tmp
- %TEMP%\ixp000.tmp\rihzw
- %APPDATA%\wuzr.exe
- %APPDATA%\rihzw
- %HOMEPATH%\xwgeektbtn9jenod\rihzw
- %HOMEPATH%\xwgeektbtn9jenod\wuzr.exe
- %TEMP%\autce56.tmp
- %TEMP%\autd02b.tmp
- %TEMP%\ixp000.tmp\jqfawc~1.exe
- %TEMP%\ixp000.tmp\rihzw
- %TEMP%\ixp000.tmp\wuzr.exe
- %TEMP%\ixp000.tmp\wuzr1
- %APPDATA%\rihzw в %HOMEPATH%\xwgeektbtn9jenod\rihzw
- %APPDATA%\wuzr.exe в %HOMEPATH%\xwgeektbtn9jenod\wuzr.exe
- DNS ASK hk#.###lightparadox.com
- '%TEMP%\ixp000.tmp\jqfawc~1.exe'
- '%APPDATA%\wuzr.exe' "%APPDATA%\RiHZW"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'
- '%WINDIR%\syswow64\notepad.exe' (со скрытым окном)
- '%TEMP%\ixp000.tmp\jqfawc~1.exe' (со скрытым окном)