Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\39F86E70.lnk
- %ALLUSERSPROFILE%\Application Data\EA1FC0CE.dll
- %ALLUSERSPROFILE%\Application Data\EA1FC0CE.dllx.bat
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\index[1].php
- %ALLUSERSPROFILE%\Application Data\F6F05D34\A5C0E4
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\index[1].php
- <Полный путь к файлу>
- %ALLUSERSPROFILE%\Application Data\F6F05D34\A5C0E4
- %ALLUSERSPROFILE%\Application Data\F6F05D34\A5C0E4
- 'localhost':1039
- '17#.#19.1.104':80
- http://17#.#19.1.104/index.php?m=########################################################################################################################
- '<SYSTEM32>\rundll32.exe' %ALLUSERSPROFILE%\Application Data\EA1FC0CE.dll,#1
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\Application Data\EA1FC0CE.dllx.bat