Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\mRcgErLiMRlZ.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mRcgErLiMRlZ.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\SNaCcilQiRkZLEO\mRcgErLiMRlZ.dll"'
- 'mRcgErLiMRlZ.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\SNaCcilQiRkZLEO\mRcgErLiMRlZ.dll"
- '<SYSTEM32>\regsvr32.exe' ..\hvxda.ocx
- %HOMEPATH%\hvxda.ocx
- <Текущая директория>\72111000
- %HOMEPATH%\hvxda.ocx в <SYSTEM32>\snaccilqirkzleo\mrcgerlimrlz.dll
- <PATH_SAMPLE>.xls
- 'of###mocity.com':443
- 'mu#####roperty.co.uk':443
- 'go#####endsdriving.com':80
- http://go#####endsdriving.com/createschedule/F0jGvgTiFAMRh2Tr8HL/
- 'of###mocity.com':443
- 'mu#####roperty.co.uk':443
- DNS ASK of###mocity.com
- DNS ASK mu#####roperty.co.uk
- DNS ASK go#####endsdriving.com
- '<SYSTEM32>\regsvr32.exe' ..\hvxda.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\SNaCcilQiRkZLEO\mRcgErLiMRlZ.dll"