Техническая информация
- %TEMP%\nsl205c.tmp\killprocdll.dll
- %TEMP%\nsl205c.tmp\dllwaitforkillprogram.dll
- %TEMP%\nsl205c.tmp\dllwebcount.dll
- %APPDATA%\livetools\ping\lps.exe
- %APPDATA%\livetools\ping\lpsagent.exe
- %TEMP%\nsl205c.tmp\selfdelete.dll
- C:\delus.bat
- %TEMP%\nsl205c.tmp\dllwaitforkillprogram.dll
- %TEMP%\nsl205c.tmp\dllwebcount.dll
- %TEMP%\nsl205c.tmp\killprocdll.dll
- %TEMP%\nsl205c.tmp\selfdelete.dll
- http://www.li###ools.co.kr/_analytics/request/count.php?mo######################
- http://www.li###ools.co.kr/_analytics/request/count.php?mo#######################
- http://pi##.##vetools.co.kr/update/update.xml
- DNS ASK li###ools.co.kr
- DNS ASK pi##.##vetools.co.kr
- '%APPDATA%\livetools\ping\lps.exe'
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c \DelUS.bat