Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'VMwares' = '%PROGRAM_FILES%\PrinC\spooles.exe'
- <SYSTEM32>\cmd.exe /c %TEMP%\4A055F9F.bat
- %PROGRAM_FILES%\PrinC\PrintC.txt
- %PROGRAM_FILES%\PrinC\PrintB.txt
- %TEMP%\4A055F9F.bat
- %PROGRAM_FILES%\PrinC\PrintA.txt
- из <Полный путь к вирусу> в %PROGRAM_FILES%\PrinC\spooles.exe
- 'ko####.baduki8.com':2200
- 'ko####.baduki8.com':800
- 'ko####.baduki8.com':200
- DNS ASK ko####.baduki8.com