Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\current.vbs
- %APPDATA%\microsoft\windows\start menu\programs\startup\propagationflags.vbs
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- %TEMP%\vnckriptor.exe
- %APPDATA%\current.exe
- %APPDATA%\propagationflags.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\installutil.exe.log
- 'bu#####eriya1c.moscow':443
- 'x1.#.lencr.org':80
- '19#.#6.227.209':5444
- http://x1.#.lencr.org/
- 'bu#####eriya1c.moscow':443
- '19#.#6.227.209':5444
- DNS ASK bu#####eriya1c.moscow
- DNS ASK x1.#.lencr.org
- '%TEMP%\vnckriptor.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe'