Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\CRNJEUFU8.LNK
- %HOMEPATH%\Start Menu\Programs\Startup\CRNJEUFU5.LNK
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wscript.exe' "%TEMP%\b.vbs"
- %APPDATA%\17731131\vgt.zip
- %TEMP%\b.vbs
- 'bl#####otosdegyn.com.br':80
- 'localhost':1038
- bl#####otosdegyn.com.br/bueno.zip
- DNS ASK bl#####otosdegyn.com.br