Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'QuickShock' = '%WINDIR%\Media\AvMsUpd.exe'
- %WINDIR%\Media\user.dat
- %WINDIR%\Media\Temp.tjp
- %WINDIR%\Media\upset1.dat
- %WINDIR%\Media\AvMsUpd.exe
- %WINDIR%\Media\Temp.tjp
- 'www.da#####xweb500.com.br':80
- 'www.up####ell600.com.br':80
- '72.##9.145.229':80
- www.da#####xweb500.com.br/ptdata/set.txt
- www.up####ell600.com.br/ptdata/CurrVer.txt
- 72.##9.145.229/ptserver/ok.php?id##
- DNS ASK www.da#####xweb500.com.br
- DNS ASK www.up####ell600.com.br
- ClassName: 'Indicator' WindowName: ''