Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'javasched' = '%APPDATA%\Microsoft\Windows\Themes\Slideshows\SlideshowService.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ViaReg' = '"%APPDATA%\ViaFolder\ViaFile.exe"'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe'
- '%TEMP%\5835544.uwa22norVia.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 756
- '%APPDATA%\Microsoft\Windows\Themes\Slideshows\SlideshowService.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe' /logtoconsole=false /logfile= /u "%APPDATA%\ViaFolder\ViaFile.EXE"
- '<SYSTEM32>\cmd.exe' /c mkdir "%APPDATA%\ViaFolder"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe' /logtoconsole=false /logfile= /u "<Полный путь к файлу>"
- '%APPDATA%\ViaFolder\ViaFile.EXE'
- '<SYSTEM32>\cmd.exe' /c type NUL>"%APPDATA%\ViaFolder\ViaFile.EXE"
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %TEMP%\dw.log
- %TEMP%\42CE8.dmp
- %APPDATA%\Microsoft\Windows\Themes\Slideshows\SlideshowService.exe
- %APPDATA%\ViaFolder\ViaFile.EXE
- %TEMP%\5835544.uwa22norVia.exe
- 'aw#.moe':443
- 'cd#.#edsec.co':80
- 'wp#d':80
- http://cd#.#edsec.co/cryptonight/stop.txt
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK aw#.moe
- DNS ASK cd#.#edsec.co
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''