Техническая информация
- '%APPDATA%\Roaming\ID Detector\detect.exe'
- %APPDATA%\Roaming\Microsoft\Windows\w1z6Bk1rhFtB2\w1z6Bk1rhFtB2.nfo
- %APPDATA%\Roaming\Microsoft\Windows\w1z6Bk1rhFtB2\w1z6Bk1rhFtB2.dat
- %APPDATA%\Roaming\Microsoft\Windows\w1z6Bk1rhFtB2\w1z6Bk1rhFtB2.svr
- %APPDATA%\Roaming\ID Detector\detect.exe
- %APPDATA%\Roaming\ID Detector\detect.bat
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ID Detector.vbs
- %APPDATA%\Roaming\Microsoft\Windows\w1z6Bk1rhFtB2\w1z6Bk1rhFtB2.svr
- %APPDATA%\Roaming\Microsoft\Windows\w1z6Bk1rhFtB2\w1z6Bk1rhFtB2.dat
- %APPDATA%\Roaming\Microsoft\Windows\w1z6Bk1rhFtB2\w1z6Bk1rhFtB2.nfo
- %APPDATA%\Roaming\Microsoft\Windows\w1z6Bk1rhFtB2\w1z6Bk1rhFtB2.svr
- %APPDATA%\Roaming\Microsoft\Windows\w1z6Bk1rhFtB2\w1z6Bk1rhFtB2.nfo
- 'de###l.ddns.net':1700
- DNS ASK dn#.##ftncsi.com
- DNS ASK de###l.ddns.net