Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Control\SecurityProviders] 'SecurityProviders' = 'msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, AyyomhucCuml.dll'
- <SYSTEM32>\rundll32.exe "<SYSTEM32>\AyyomhucCuml.dll",EntryPoint
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\AyyomhucCuml.dll
- 'ma##.gmail.com':25
- 'go####baby12.com':1001
- '67.##5.160.76':25
- 'ma##.#otmail.com':25
- DNS ASK HO##aIl.cOM
- DNS ASK GM##l.cOM
- DNS ASK YA##O.Com
- DNS ASK go####baby12.com
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''