Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '%APPDATA%\FacebookVideoCall.exe'
- %TEMP%\trip.exe
- %TEMP%\plugtmp\svchost.exe
- %APPDATA%\FacebookVideoCall.exe
- %TEMP%\trip.exe
- %TEMP%\plugtmp\2012.ine
- %TEMP%\plugtmp\svchost.exe
- 'wo####ip.zapto.org':6969
- DNS ASK wo####ip.zapto.org
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MAINFRM_TRIPCODE_EXPLORER' WindowName: ''