Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'w1ndows_bf8f' = '%APPDATA%\w1ndows_bf8f.exe'
- %APPDATA%\w1ndows_bf8f.exe
- %APPDATA%\i.txt
- %APPDATA%\c.txt
- %TEMP%\php1.tmp
- %TEMP%\php2.tmp
- %TEMP%\php3.tmp
- 'pc####nder.co.vu':80
- pc####nder.co.vu/api.php?co###
- DNS ASK pc####nder.co.vu
- ClassName: 'Indicator' WindowName: '(null)'