Техническая информация
- %WINDIR%\Tasks\imbdhsd.job
- '%TEMP%\greddfe.exe'
- %HOMEPATH%\My Documents\DecryptAllFiles 195453.txt
- %HOMEPATH%\My Documents\AllFilesAreLocked 195468.bmp
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\desktop.ini
- %APPDATA%\Microsoft\wqnwaoa
- %TEMP%\greddfe.exe
- %HOMEPATH%\My Documents\dpedqad.html
- %WINDIR%\Tasks\imbdhsd.job
- 'yh######ppkt7bie.onion.cab':443
- '19#.#09.206.212':443
- 'yh#######pkt7bie.tor2web.org':443
- 'localhost':1036
- 'ip.##lize.com':80
- '76.##.17.194':9090
- ip.##lize.com/
- DNS ASK yh#######pkt7bie.tor2web.org
- DNS ASK yh######ppkt7bie.onion.cab
- DNS ASK ip.##lize.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''