Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Odsjbp Lncgfmrn Njl] 'Start' = '00000002'
- %WINDIR%\Misxobqyl.exe
- <SYSTEM32>\cmd.exe /c """%TEMP%\Temp\3D.exe.bat"" "
- <SYSTEM32>\cmd.exe /c """%TEMP%\Temp\і¬ј¶±ИЕЖЧўІбВлЙъіЙЖч.exe.bat"" "
- %TEMP%\Temp\3D.exe.bat
- %WINDIR%\Misxobqyl.exe
- %TEMP%\Temp\і¬ј¶±ИЕЖЧўІбВлЙъіЙЖч.exe.bat
- %TEMP%\Temp\і¬ј¶±ИЕЖЧўІбВлЙъіЙЖч.exe
- %TEMP%\Temp\3D.exe
- %TEMP%\Temp\3D.exe
- 'he####g.meibu.com':5800
- DNS ASK he####g.meibu.com
- ClassName: 'Shell_TrayWnd' WindowName: ''