Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\YKeSUWxSfcIN.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\YKeSUWxSfcIN.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\VEZplfcZ\YKeSUWxSfcIN.dll"'
- 'YKeSUWxSfcIN.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\VEZplfcZ\YKeSUWxSfcIN.dll"
- '<SYSTEM32>\regsvr32.exe' ..\vhdxw.ocx
- %HOMEPATH%\vhdxw.ocx
- <Текущая директория>\d9131000
- %HOMEPATH%\vhdxw.ocx в <SYSTEM32>\vezplfcz\ykesuwxsfcin.dll
- <PATH_SAMPLE>.xls
- 'an###anoss.com':80
- 'is#####echnologies.com':80
- '10#.#48.225.227':8080
- '18#.#25.32.231':4143
- '21#.#7.209.142':8080
- '5.##.132.177':8080
- '45.##.195.104':8080
- '85.##4.67.203':8080
- '54.##.106.167':8080
- '36.#7.23.59':443
- '37.##.209.141':8080
- '62.##1.178.147':8080
- '19#.#.172.107':8080
- '13#.#96.72.155':8080
- '20#.#48.81.119':8080
- '19#.#7.239.39':8080
- http://www.is#####echnologies.com/blogs/LjCTItLtHGBM4S3/
- '10#.#48.225.227':8080
- '18#.#25.32.231':4143
- '54.##.106.167':8080
- '13#.#96.72.155':8080
- DNS ASK an###anoss.com
- DNS ASK is#####echnologies.com
- '<SYSTEM32>\regsvr32.exe' ..\vhdxw.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\VEZplfcZ\YKeSUWxSfcIN.dll"