Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%HOMEPATH%\ydwzro.exe'
- %WINDIR%\syswow64\svchost.exe
- %HOMEPATH%\ydwzro.exe
- %HOMEPATH%\ydwzro.exe
- DNS ASK je####.ananikolic.su
- DNS ASK pe##.##ckeklosarske.ru
- DNS ASK te###.#ornicarke.com
- DNS ASK ju###.#osmibracala.org
- 'te###.#ornicarke.com':6600
- 'ju###.#osmibracala.org':6600
- '%WINDIR%\syswow64\svchost.exe'