Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\WnD8tPoJ8McCNO4g\whrgEmeu1Ulv.exe",explorer.exe'
- '%TEMP%\2HZkfvl4eA1KX6bN.exe'
- %TEMP%\Jex68xZk1E1xluyA
- %APPDATA%\Imminent\Logs\08-01-2015
- %APPDATA%\WnD8tPoJ8McCNO4g\whrgEmeu1Ulv.exe
- %TEMP%\2HZkfvl4eA1KX6bN.exe
- %APPDATA%\WnD8tPoJ8McCNO4g\whrgEmeu1Ulv.exe
- 'lo######fe.servebeer.com':9003
- DNS ASK lo######fe.servebeer.com
- ClassName: 'Shell_TrayWnd' WindowName: ''