Техническая информация
- '<SYSTEM32>\svchost.exe' ext "<Полный путь к вирусу>"
- <SYSTEM32>\svchost.exe
- %APPDATA%\Roaming\tor\hidden_service\hostname.tmp
- %TEMP%\OpenCL.dll
- %APPDATA%\Roaming\tor\state.tmp
- %APPDATA%\Roaming\tor\hidden_service\private_key.tmp
- %APPDATA%\Roaming\tor\hidden_service\hostname.tmp в %APPDATA%\Roaming\tor\hidden_service\hostname
- %APPDATA%\Roaming\tor\hidden_service\private_key.tmp в %APPDATA%\Roaming\tor\hidden_service\private_key
- %APPDATA%\Roaming\tor\state.tmp в %APPDATA%\Roaming\tor\state
- '19#.#3.244.244':443
- 'localhost':9050
- 'localhost':49166
- '15#.35.32.5':443
- DNS ASK dn#.##ftncsi.com
- DNS ASK ch####p.dyndns.org
- ClassName: 'Shell_TrayWnd' WindowName: ''