Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsHost' = '%APPDATA%\WinHost\svchost.exe'
- %APPDATA%\WinHost\svchost.exe
- <SYSTEM32>\svchost.exe
- %WINDIR%\Explorer.EXE
- %APPDATA%\WinHost\svchost.exe
- 'no####ok-sleeve.biz':80
- 'no####ok-blog.asia':80
- 'do####notebook.biz':80
- 'ge####gcorny.biz':80
- 'co###pickup.biz':80
- 'sl##rs.com':80
- 'en###deyu.com':80
- 'ge##sb.com':80
- 'no###ookkids.in':80
- 'ar###haj.com':80
- no####ok-sleeve.biz/entrez/gabel.php
- no####ok-blog.asia/entrez/gabel.php
- do####notebook.biz/entrez/gabel.php
- ge####gcorny.biz/entrez/gabel.php
- co###pickup.biz/entrez/gabel.php
- sl##rs.com/entrez/gabel.php
- en###deyu.com/entrez/gabel.php
- ge##sb.com/entrez/gabel.php
- no###ookkids.in/entrez/gabel.php
- ar###haj.com/entrez/gabel.php
- DNS ASK no####ok-sleeve.biz
- DNS ASK no####ok-blog.asia
- DNS ASK do####notebook.biz
- DNS ASK ge####gcorny.biz
- DNS ASK co###pickup.biz
- DNS ASK sl##rs.com
- DNS ASK en###deyu.com
- DNS ASK ge##sb.com
- DNS ASK no###ookkids.in
- DNS ASK ar###haj.com
- ClassName: 'Indicator' WindowName: ''