Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\Roaming\6ubez7b6m6LkHHRW\imLnuZzoWISi.exe",explorer.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %APPDATA%\Roaming\Microsoft\Windows\W94cAWw6\W94cAWw6.svr
- %APPDATA%\Roaming\Microsoft\Windows\W94cAWw6\W94cAWw6.nfo
- %APPDATA%\Roaming\6ubez7b6m6LkHHRW\imLnuZzoWISi.exe
- %APPDATA%\Roaming\Microsoft\Windows\W94cAWw6\W94cAWw6.svr
- %APPDATA%\Roaming\Microsoft\Windows\W94cAWw6\W94cAWw6.nfo
- %APPDATA%\Roaming\6ubez7b6m6LkHHRW\imLnuZzoWISi.exe
- %APPDATA%\Roaming\Microsoft\Windows\W94cAWw6\W94cAWw6.svr
- DNS ASK jh#.#uckdns.org
- DNS ASK cv##.webhop.me
- DNS ASK je####4mi.noip.me
- DNS ASK dn#.##ftncsi.com
- ClassName: 'Shell_TrayWnd' WindowName: ''