Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sppsvc' = '%ALLUSERSPROFILE%\application data\QicAZ5EI\sppsvc.exe'
- %ALLUSERSPROFILE%\Application Data\QicAZ5EI\data\dwm.bmp
- %ALLUSERSPROFILE%\Application Data\QicAZ5EI\data\dwm.dll
- %ALLUSERSPROFILE%\Application Data\QicAZ5EI\updata.log
- %ALLUSERSPROFILE%\Application Data\QicAZ5EI\sppsvc.txt
- %ALLUSERSPROFILE%\Application Data\QicAZ5EI\sppsvc.exe
- %ALLUSERSPROFILE%\Application Data\QicAZ5EI\data\dwm.dll
- %ALLUSERSPROFILE%\Application Data\QicAZ5EI\data\dwm.bmp
- %ALLUSERSPROFILE%\Application Data\QicAZ5EI\sppsvc.txt
- 'www.fy###side.com':80
- 'localhost':1038
- 'gi##ub.com':80
- http://www.fy###side.com/dwm99.bmp
- http://gi##ub.com/NordicMyth/NordicMyth/blob/master/README2.md
- DNS ASK www.fy###side.com
- DNS ASK gi##ub.com