Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'xcrx' = '<SYSTEM32>\Coffin Of Evil.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'xdocx' = '<SYSTEM32>\Coffin Of Evil.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{4RG154YH-VMXC-508T-BA2C-F13MXN64317W}] 'StubPath' = '<SYSTEM32>\Coffin Of Evil.exe Restart'
- '%HOMEPATH%\My Documents\Server.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen <LS_APPDATA>VsjDQJMxOB.jpg
- '<LS_APPDATA>HhdrkZMnnq.exe'
- <SYSTEM32>\Coffin Of Evil.exe
- <SYSTEM32>\logs.dat
- %HOMEPATH%\My Documents\Server.exe
- <LS_APPDATA>HhdrkZMnnq.exe
- <LS_APPDATA>VsjDQJMxOB.jpg
- <SYSTEM32>\logs.dat
- 'as####d.ddns.net':288
- DNS ASK as####d.ddns.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''