Техническая информация
- Средство контроля пользовательских учетных записей (UAC)
- ieinstal.exe
- %APPDATA%\remcos\logs.dat
- 'wi####e247.ddns.net':3435
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- DNS ASK drive.google.com
- DNS ASK microsoft.com
- DNS ASK do#########ocs.googleusercontent.com
- DNS ASK wi####e247.ddns.net
- DNS ASK oc##.thawte.com
- '%ProgramFiles(x86)%\internet explorer\ieinstal.exe'
- '%WINDIR%\syswow64\cmd.exe' <SYSTEM32>\reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
- '%WINDIR%\syswow64\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f