Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'VFXGNxv++pP' = '<LS_APPDATA>\Microsoft\Windows\nbcaxlo.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %TEMP%\cdsowrshn.tmp
- <LS_APPDATA>\Microsoft\Windows\nbcaxlo.exe
- %TEMP%\cdsowrshn.tmp
- '46.##5.206.252':80
- http://46.##5.206.252/QWRsN2srdjlxUUdDYVp0aTBMUzl2Kyt1RkxLRVBhQmtZZjZWeVRkNnlzT3llckp4S3dPV3ZNS3NrY3J2OHI2YUQxdnB3WnhXaHRERlZzZ0F1c0ZiSU81aGNmQnk0cHZhbUxNeTBMUmlRL1ZDenI0NThTeU9xZW94ZTEzQ0ZTNFp...
- http://46.##5.206.252/
- ClassName: 'Indicator' WindowName: ''