Техническая информация
- '<SYSTEM32>\svchost.exe' ext "<Полный путь к вирусу>"
- <SYSTEM32>\svchost.exe
- %APPDATA%\Roaming\tor\hidden_service\hostname.tmp
- %TEMP%\OpenCL.dll
- %APPDATA%\Roaming\tor\state.tmp
- %APPDATA%\Roaming\tor\hidden_service\private_key.tmp
- %APPDATA%\Roaming\tor\hidden_service\hostname.tmp в %APPDATA%\Roaming\tor\hidden_service\hostname
- %APPDATA%\Roaming\tor\hidden_service\private_key.tmp в %APPDATA%\Roaming\tor\hidden_service\private_key
- %APPDATA%\Roaming\tor\state.tmp в %APPDATA%\Roaming\tor\state
- 'localhost':9050
- '20#.#3.223.34':80
- 'localhost':49167
- DNS ASK dn#.##ftncsi.com
- DNS ASK ch####p.dyndns.org
- ClassName: 'Shell_TrayWnd' WindowName: ''