Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Goal' = '%APPDATA%\BicoZC2wt.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Goal' = '%APPDATA%\BicoZC2wt.exe'
- %APPDATA%\BicoZC2wt.exe
- %APPDATA%\Microsoft\Protect\Credentials\wldsvcm.exe (загружен из сети Интернет)
- %WINDIR%\Explorer.EXE
- %APPDATA%\BicoZC2wt.exe
- %APPDATA%\Microsoft\Protect\Credentials\wldsvcm.exe
- %APPDATA%\Microsoft\Protect\Credentials\wldsvc.exe
- %APPDATA%\BicoZC2wt.exe
- %APPDATA%\Microsoft\Protect\Credentials\wldsvc.exe
- 'ju###lon.com':9872
- 'ww####.megaupload.com':80
- ww####.megaupload.com/files/be7cbbe2fb56a15e53ef6e4150e5bce0/wldsvcm.exe
- DNS ASK ju###lon.com
- DNS ASK ww####.megaupload.com
- '10.#.1.1':1035
- ClassName: 'Indicator' WindowName: ''