Техническая информация
- %WINDIR%\tasks\nutritioncount.job
- [<HKLM>\System\CurrentControlSet\Services\Devoted Group] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Devoted Group] 'ImagePath' = '%APPDATA%\Devoted Group\Devoted Group.exe'
- %APPDATA%\devoted group\devoted group.exe
- %ALLUSERSPROFILE%\application data\{28756ce0-7580-394c-2875-56ce0758b381}\<Имя файла>.exe
- %APPDATA%\devoted group\juy.dat
- %ALLUSERSPROFILE%\application data\{28756ce0-7580-394c-2875-56ce0758b381}\<Имя файла>.dat
- DNS ASK mo###odel.biz
- DNS ASK al####el-pro.com
- DNS ASK fu###et.link
- DNS ASK pa###tmodel.biz
- '%APPDATA%\devoted group\devoted group.exe'