Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = ' '
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\ff39eb65] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ff39eb65] 'ImagePath' = '"<SYSTEM32>\rundll32.exe" "%ProgramFiles(x86)%\coolsoft\coolsoft.dll",serv'
- %TEMP%\tf266f17f4.dll
- %ProgramFiles(x86)%\coolsoft\coolsoft.dll
- %TEMP%\tf266f17f4.dll
- 'ed###on.cnn.com':80
- DNS ASK ed###on.cnn.com
- DNS ASK te###ne.info
- DNS ASK te##ine.net
- DNS ASK fa###rygood.net
- '%WINDIR%\syswow64\rundll32.exe' "%ProgramFiles(x86)%\coolsoft\coolsoft.dll",serv -install
- '<SYSTEM32>\rundll32.exe' "%ProgramFiles(x86)%\coolsoft\coolsoft.dll",serv