Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '1' = '%HOMEPATH%\Local Settings\MicrosoftUpdate\reader.exe /run'
- %HOMEPATH%\Local Settings\MicrosoftUpdate\reader.exe
- %HOMEPATH%\Local Settings\MicrosoftUpdate\ciner.zip
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\coin[1].zip
- 'cr####onemin.com':80
- cr####onemin.com/comentest/stat.php?vi#####
- cr####onemin.com/comentest/coin.zip
- DNS ASK cr####onemin.com