Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\HEusgbKw.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\HEusgbKw.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\QdYDDwtpH\HEusgbKw.dll"'
- 'HEusgbKw.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\QdYDDwtpH\HEusgbKw.dll"
- '<SYSTEM32>\regsvr32.exe' ..\dxven.ocx
- %HOMEPATH%\dxven.ocx
- <Текущая директория>\a5661000
- %HOMEPATH%\dxven.ocx в <SYSTEM32>\qdyddwtph\heusgbkw.dll
- <PATH_SAMPLE>.xls
- 'st#####ymarketing.com':443
- 'fu###a99fm.com':80
- http://fu###a99fm.com/cgi-bin/hm5Bi66/
- 'st#####ymarketing.com':443
- DNS ASK st#####ymarketing.com
- DNS ASK fu###a99fm.com
- '<SYSTEM32>\regsvr32.exe' ..\dxven.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\QdYDDwtpH\HEusgbKw.dll"