Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\YuDCSG.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\YuDCSG.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\QgxUQyMDyFGr\YuDCSG.dll"'
- 'YuDCSG.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\QgxUQyMDyFGr\YuDCSG.dll"
- '<SYSTEM32>\regsvr32.exe' ..\xwnlm.ocx
- %HOMEPATH%\xwnlm.ocx
- <Текущая директория>\da831000
- %HOMEPATH%\xwnlm.ocx в <SYSTEM32>\qgxuqymdyfgr\yudcsg.dll
- <PATH_SAMPLE>.xls
- 'li##us.com':443
- 'kr###str.com':80
- http://kr###str.com/tr/bbRjEuBFYBX4Oiod/
- 'li##us.com':443
- DNS ASK li##us.com
- DNS ASK kr###str.com
- '<SYSTEM32>\regsvr32.exe' ..\xwnlm.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\QgxUQyMDyFGr\YuDCSG.dll"