Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'UpdEleysDrvX32z' = '"%APPDATA%\UpdExplersDrv32Xz\wuvasicevu.exe"'
- '<SYSTEM32>\svchost.exe'
- %APPDATA%\UpdExplersDrv32Xz\UpdExplerDrz.jpg
- %APPDATA%\UpdExplersDrv32Xz\wuvasicevu.exe
- <SYSTEM32>\config\SecEvent.Evt
- %APPDATA%\UpdExplersDrv32Xz\UpdExplerDrz.jpg
- <SYSTEM32>\config\AppEvent.Evt
- <SYSTEM32>\config\SysEvent.Evt
- 'ex###leusd.pw':80
- 'localhost':1036
- ex###leusd.pw/upd.php
- ex###leusd.pw/files2/i.jpg
- DNS ASK ex###leusd.pw
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: ''