Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] '*EvtMgr32' = '%WINDIR%\{01044D45-6B75-1FE8-7744-CA3E1F40881D}.exe'
- '%WINDIR%\{01044D45-6B75-1FE8-7744-CA3E1F40881D}.exe' /mw
- '%WINDIR%\{01044D45-6B75-1FE8-7744-CA3E1F40881D}.exe' /rm "<Полный путь к вирусу>"
- %WINDIR%\{01044D45-6B75-1FE8-7744-CA3E1F40881D}.exe
- %WINDIR%\{01044D45-6B75-1FE8-7744-CA3E1F40881D}.exe
- 'www.ip###cation.com':80
- www.ip###cation.com/
- DNS ASK www.ip###cation.com