Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\desktop.ini
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Desktop.lnk
- <SYSTEM32>\svchost.exe
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'Regmonclass', WindowName: ''
- 'u2.##rryblog.pw':80
- 'to#.##rryblog.pw':3888
- http://u2.##rryblog.pw/1.php
- DNS ASK u2.##rryblog.pw
- DNS ASK to#.##rryblog.pw
- ClassName: '18467-41' WindowName: ''
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\svchost.exe' -o tok.harryblog.pw:3888 -u zxpt@s.proprietativalcea.ro -p x -B --donate-level 1 --cpu-priority 0 --max-cpu-usage=15 --safe