Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\agtNyMDs.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\agtNyMDs.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\ISljwW\agtNyMDs.dll"'
- 'agtNyMDs.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\ISljwW\agtNyMDs.dll"
- '<SYSTEM32>\regsvr32.exe' ..\hvxda.ocx
- %HOMEPATH%\hvxda.ocx
- <Текущая директория>\e0a31000
- %HOMEPATH%\hvxda.ocx в <SYSTEM32>\isljww\agtnymds.dll
- <PATH_SAMPLE>.xls
- 'th#####icelection.com':443
- 'ea######mmunications.com':80
- http://ea######mmunications.com/wp-content/09i4dfKbpiuj8k/
- 'th#####icelection.com':443
- DNS ASK th#####icelection.com
- DNS ASK ea######mmunications.com
- '<SYSTEM32>\regsvr32.exe' ..\hvxda.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\ISljwW\agtNyMDs.dll"