Техническая информация
- '%TEMP%\csrvc\BSOD.exe'
- '%TEMP%\csrvc\BSOD.exe' (загружен из сети Интернет)
- '<SYSTEM32>\sc.exe' config "csrvc" type= interact type= own
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' http://go.##clasrv.com/afu.php?id########
- '<SYSTEM32>\sc.exe' config "csrvc" start=auto
- '<SYSTEM32>\sc.exe' failure "csrvc" reset= 0 actions= restart/60000
- %TEMP%\csrvc\csrvc.exe
- %TEMP%\csrvc\BSOD.exe
- '18#.#0.133.109':139
- '18#.#0.133.109':445
- 'go.##clasrv.com':80
- 'localhost':1065
- '18#.#0.133.109':1433
- 'hi####novation.com':80
- 'wp#d':80
- 'fr###eoip.net':80
- 'ip##fo.io':80
- http://ip##fo.io/ip
- http://fr###eoip.net/xml
- http://go.##clasrv.com/afu.php?id########
- http://11#.#11.111.1/wpad.dat via wp#d
- http://hi####novation.com/Downloads/Files/BSOD.exe
- http://hi####novation.com/Downloads/Files/csrvc.exe
- DNS ASK fr###eoip.net
- DNS ASK go.##clasrv.com
- DNS ASK ip##fo.io
- DNS ASK wp#d
- DNS ASK hi####novation.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: ''