Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Orbiter] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k ORBTR
- %PROGRAM_FILES%\ORBTR\orbiter.dll
- %PROGRAM_FILES%\ORBTR\uninstall.exe
- %PROGRAM_FILES%\ORBTR\Orbt.ext
- %TEMP%\inet_orbiter.txt
- %TEMP%\nsbBF2.tmp\System.dll
- %TEMP%\nsbBF2.tmp\OrbiterTool.dll
- %TEMP%\nsbBF2.tmp\inetc.dll
- %TEMP%\nsbBF2.tmp\OrbiterTool.dll
- %TEMP%\nsbBF2.tmp\System.dll
- %TEMP%\inet_orbiter.txt
- %TEMP%\nsbBF2.tmp\inetc.dll
- 'or#######ve-msg.databssint.com':80
- 'sp######rage.spccint.com':80
- 'or#######taller.databssint.com':80
- sp######rage.spccint.com/Detection/SPDetector.exe
- or#######ve-msg.databssint.com/
- or#######taller.databssint.com/
- DNS ASK or#######ve-msg.databssint.com
- DNS ASK sp######rage.spccint.com
- DNS ASK or#######taller.databssint.com