Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SfKg6wIPu' = '%APPDATA%\Microsoft\Windows\krdasxq.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinButler' = '%APPDATA%\WinButler\WinButler.exe'
- %APPDATA%\WinButler\WinButler.exe -sa channel1 /install
- %APPDATA%\Microsoft\Windows\krdasxq.exe
- %TEMP%\WinBinstaller.exe -f %HOMEPATH%\Local Settings\Temp
- %APPDATA%\WinButler\WinBuninstaller.exe
- %APPDATA%\WinButler\config.cfg
- %TEMP%\wbff.dll
- %TEMP%\tmp2.tmp
- %APPDATA%\Microsoft\Windows\krdasxq.exe
- %APPDATA%\WinButler\WinButler.exe
- %TEMP%\WinBuninstaller.exe
- %TEMP%\config.cfg
- %TEMP%\WinButler.exe
- %TEMP%\ide21201.vxd
- %TEMP%\WinBrec.exe
- %TEMP%\WinBinstaller.exe
- %TEMP%\WinButler.exe
- %TEMP%\WinBrec.exe
- %TEMP%\config.cfg
- %TEMP%\WinBuninstaller.exe
- 'www.wi###tler.com':80
- www.wi###tler.com/fbck.php
- DNS ASK www.wi###tler.com
- ClassName: '' WindowName: ''
- ClassName: 'Indicator' WindowName: ''