Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'abada' = '%APPDATA%\Microsoft\Windows\Templates\ghenting.exe'
- qofyegkfd.exe
- [HKCU\Software\FTPWare\COREFTP\Sites\]
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions\]
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- C:\users\public\qofyegkfd.exe
- %APPDATA%\microsoft\windows\templates\zgvnhspfapv-user\logindata
- %APPDATA%\microsoft\windows\templates\zgvnhspfapv-user\webdata
- %APPDATA%\microsoft\windows\templates\ghenting.exe
- 'sh##ip.net':80
- http://sh##ip.net/
- DNS ASK sh##ip.net
- 'C:\users\public\qofyegkfd.exe'