Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Mnopqr Tuvwxyab Def] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Mnopqr Tuvwxyab Def] 'ImagePath' = '%ProgramFiles(x86)%\Google\Google.cos'
- 'Mnopqr Tuvwxyab Def' %ProgramFiles(x86)%\Google\Google.cos
- %ProgramFiles%\apppatch\mysqld.dll
- %ProgramFiles(x86)%\google\google.cos
- C:\5348.vbs
- C:\5348.vbs
- http://dj####.f3322.net:808/Consys21.dll via dj####.f3322.net
- DNS ASK dj####.f3322.net
- '%ProgramFiles(x86)%\google\google.cos'
- '%WINDIR%\syswow64\wscript.exe' "C:\5348.vbs"
- '%ProgramFiles(x86)%\google\google.cos' Win7
- '%WINDIR%\syswow64\wscript.exe' "C:\5348.vbs"' (со скрытым окном)