Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\NlsData0001] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\NlsData0001] 'ImagePath' = '"%WINDIR%\SysWOW64\NlsData0001\NlsData0001.exe"'
- из <Полный путь к файлу> в %WINDIR%\syswow64\nlsdata0001\nlsdata0001.exe
- '16#.#8.233.114':80
- '17#.#3.167.120':8080
- '12#.#50.175.133':443
- http://17#.##.167.120:8080/k6CtOYmnEf/gnwLQ1mP7WIKSs1xX/RzgXXAYacoXOVFLec/pUKcDcLaXQupPWgw/zdMEAKvqM/ via 17#.#3.167.120
- http://12#.##0.175.133:443/m7ZebwZQN7pmq/FVESCzHAp6hu8u/ via 12#.#50.175.133