Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft .NET Framework NGEN v4.0.30319_X86 Monitor' = '<LS_APPDATA>\PWD\ntageofconan.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<LS_APPDATA>\PWD\ntageofconan.exe' = '<LS_APPDATA>\PWD\ntageofconan.ex...
- '<LS_APPDATA>\PWD\ntbdss.exe'
- '<LS_APPDATA>\PWD\ntageofconan.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "<LS_APPDATA>\PWD\ntageofconan.exe" "Microsoft .NET Framework NGEN v4.0.30319_X86 Monitor" ENABLE
- <LS_APPDATA>\PWD\ntbdss.exe
- <LS_APPDATA>\PWD\ntageofconan.exe
- 'ad###findgo.com':80
- 'so####arfounds.com':80
- http://ad###findgo.com/search.php
- http://so####arfounds.com/ne.php
- DNS ASK ad###findgo.com
- DNS ASK so####arfounds.com