Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'YmEwGJXgpidLPI' = '%ALLUSERSPROFILE%\YmEwGJXgpidLPI.exe'
- Диспетчера задач (Taskmgr)
- [HKCU\Software\Microsoft\Internet Explorer\Download] 'CheckExeSignatures' = 'no'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] 'SaveZoneInformation' = '00000001'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq...
- %ALLUSERSPROFILE%\ymewgjxgpidlpi.exe
- из <Полный путь к файлу> в %TEMP%\tmpe907.tmp
- 'li##club.in':80
- 'li##club.in':443
- http://li##club.in/pica1/440-direct
- 'li##club.in':443
- DNS ASK pu##ij.in
- DNS ASK de##vee.in
- DNS ASK re##ity.in
- DNS ASK fi###lert.org
- DNS ASK lo##ra.in
- DNS ASK li##club.in
- '%ALLUSERSPROFILE%\ymewgjxgpidlpi.exe'