Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Upgrade RPC Extender Copy Propagation' = '%APPDATA%\cmsreubotijulxc\zguadoikh.exe'
- '%APPDATA%\cmsreubotijulxc\mpkvsamifooo.exe' "%APPDATA%\cmsreubotijulxc\zguadoikh.exe"
- '%APPDATA%\cmsreubotijulxc\zguadoikh.exe'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- %APPDATA%\cmsreubotijulxc\zguadoikh.se1i
- %APPDATA%\cmsreubotijulxc\mpkvsamifooo.exe
- %APPDATA%\cmsreubotijulxc\zguadoikh.exe
- %APPDATA%\cmsreubotijulxc\zguadoikh.exe
- 'th####hvalley.net':80
- http://th####hvalley.net/index.php?em######################################
- DNS ASK in####sesilver.net
- DNS ASK fo####sister.net
- DNS ASK in####sesister.net
- DNS ASK fo####silver.net
- DNS ASK th####hvalley.net
- DNS ASK ef###tlabor.net
- DNS ASK th####hlabor.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''