Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Startup Key' = '%TEMP%\gew.exe'
- '%TEMP%\NbYHUttVdpSlRoHgHSMeOkUfkhsKYghqPKmoVbuD.exe'
- '%TEMP%\NbYHUttVdpSlRoHgHSMeOkUfkhsKYghqPKmoVbuD.exe' (загружен из сети Интернет)
- %TEMP%\gew.exe
- %TEMP%\NbYHUttVdpSlRoHgHSMeOkUfkhsKYghqPKmoVbuD.exe
- %TEMP%\NbYHUttVdpSlRoHgHSMeOkUfkhsKYghqPKmoVbuD.exe
- 'www.wh###myip.us':80
- 'sm##.gmail.com':587
- 'wp#d':80
- 'go#.gl':80
- www.wh###myip.us/showipsimple.php
- go#.gl/7j1tGS
- wp#d/wpad.dat
- DNS ASK www.wh###myip.us
- DNS ASK sm##.gmail.com
- DNS ASK wp#d
- DNS ASK go#.gl
- ClassName: 'Indicator' WindowName: '(null)'