Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SysInfo' = '<SYSTEM32>\sshjp32.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Info' = '<SYSTEM32>\bootok.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Info' = '<SYSTEM32>\bootok.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SysInfo' = '<SYSTEM32>\bootok.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'CurrentLevel' = '00000000'
- 'ds###ain.com':80
- 'ds###ain.com':443
- http://ds###ain.com/temp/hs.txt
- http://ds###ain.com/temp/123_.dll
- http://ds###ain.com/temp/123_.exe
- http://ds###ain.com/temp/123i_.exe
- http://ds###ain.com/temp/123b_.txt
- 'ds###ain.com':443
- DNS ASK ds###ain.com