Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Repay' = '<LS_APPDATA>\Repay\RpCounter.exe'
- <LS_APPDATA>\Repay\RpCounter.exe /install
- <LS_APPDATA>\Repay\msvcr71.dll
- <LS_APPDATA>\Repay\msi.ico
- <LS_APPDATA>\Repay\uninst.exe
- <LS_APPDATA>\Repay\RpCounter.exe
- %TEMP%\nsz2.tmp\System.dll
- <LS_APPDATA>\Repay\Repay.dll
- <LS_APPDATA>\Repay\readme.txt
- 'ea###con.co.kr':80
- ea###con.co.kr/count/check2.php
- ea###con.co.kr/_admin/program/activate2.html
- ea###con.co.kr/count/inst.php?pc##############################
- DNS ASK ea###con.co.kr
- ClassName: 'Indicator' WindowName: ''