Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'gmrghoeltw' = '"%APPDATA%\gmrghoeltw.exe"'
- %HOMEPATH%\Start Menu\Programs\Startup\gmrghoeltw.vbs
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe' "%APPDATA%\gmrghoeltw.exe" CkvJcFLFlG DWzfVKBHdF
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
- 'gd#######sgbanbknakfgarkang.com':80
- 'nj#######lifhauierhfabva.com':80
- 'kh#######hkjfhafljhajkfhv.com':80
- 'wp#d':80
- 'my####rnalip.com':80
- http://my####rnalip.com/raw
- http://11#.#11.111.1/wpad.dat via wp#d
- http://nj#######lifhauierhfabva.com/gate.php
- http://gd#######sgbanbknakfgarkang.com/gate.php
- http://kh#######hkjfhafljhajkfhv.com/gate.php
- DNS ASK gd#######sgbanbknakfgarkang.com
- DNS ASK nj#######lifhauierhfabva.com
- DNS ASK kh#######hkjfhafljhajkfhv.com
- DNS ASK wp#d
- DNS ASK my####rnalip.com
- ClassName: 'Indicator' WindowName: ''