Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'aspuwn.exe' = '%APPDATA%\Roaming\aselud\\aspuwn.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'eplabu.exe' = '%APPDATA%\Roaming\aselud\eplabu.exe'
- '%APPDATA%\Roaming\aselud\eplabu.exe'
- %APPDATA%\Roaming\aselud\eplabu.exe
- %TEMP%\~DF253ADE4C16D637AC.TMP
- %TEMP%\~DF0244FD365C1D344B.TMP
- 'at####loader.biz':80
- at####loader.biz/premium-load2/82ii.php?h=#######################################################################
- at####loader.biz/premium-load2/BTC.php
- DNS ASK at####loader.biz
- ClassName: 'Indicator' WindowName: '(null)'