Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'NBKJBVKJBK' = '%APPDATA%\Roaming\NBKJBVKJYT\Svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'NBKJBVKJBK' = '\NBKJBVKJYT\Svchost.exe'
- '<SYSTEM32>\rundll32.exe' dfdts.dll,DfdGetDefaultPolicyAndSMART
- %APPDATA%\Roaming\Imminent\Logs\15-07-2014
- %APPDATA%\Roaming\Imminent\Path.dat
- C:\NBKJBVKJYT\Svchost.exe
- %APPDATA%\Roaming\NBKJBVKJYT\Svchost.exe
- 'st######sciple.no-ip.biz':9003
- DNS ASK dn#.##ftncsi.com
- DNS ASK st######sciple.no-ip.biz
- ClassName: 'Indicator' WindowName: ''