Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'TCP Service' = '%PROGRAM_FILES%\TCP Service\tcpsv.exe'
- '<SYSTEM32>\rundll32.exe' dfdts.dll,DfdGetDefaultPolicyAndSMART
- '<SYSTEM32>\schtasks.exe' /create /f /tn "TCP Service Task" /xml "%TEMP%\tmp31F9.tmp"
- '<SYSTEM32>\schtasks.exe' /create /f /tn "TCP Service" /xml "%TEMP%\tmp2E8E.tmp"
- %APPDATA%\Roaming\FDAAD129-04DF-4089-BB80-174CE725F721\task.dat
- %TEMP%\tmp31F9.tmp
- <SYSTEM32>\Tasks\TCP Service Task
- <SYSTEM32>\Tasks\TCP Service
- %APPDATA%\Roaming\FDAAD129-04DF-4089-BB80-174CE725F721\run.dat
- %PROGRAM_FILES%\TCP Service\tcpsv.exe
- %TEMP%\tmp2E8E.tmp
- %TEMP%\tmp31F9.tmp
- %TEMP%\tmp2E8E.tmp
- 'ay###.no-ip.org':1999
- 'ay####.no-ip.org':1999
- DNS ASK ay###.no-ip.org
- DNS ASK dn#.##ftncsi.com
- DNS ASK ay####.no-ip.org