Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Taskman' = '%APPDATA%\vfbu.exe'
- %WINDIR%\Explorer.EXE
- iexplore.exe
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'RegMonClass' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- %APPDATA%\vfbu.exe
- %TEMP%\2B34E233.TMP
- %APPDATA%\vfbu.exe
- DNS ASK up####windows.net
- DNS ASK p�#
- DNS ASK li####dates2000.com
- DNS ASK �:##@�
- ClassName: 'Progman' WindowName: ''