Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SolService' = '%LOCALAPPDATA%\Microsoft\sysprotect.exe'
- %WINDIR%\syswow64\explorer.exe
- %LOCALAPPDATA%\microsoft\temporary.dat
- %LOCALAPPDATA%\microsoft\sysprotect.exe
- 'ip###ger.org':443
- 'cd#.##scordapp.com':443
- 'ip###ger.org':443
- 'cd#.##scordapp.com':443
- DNS ASK ip###ger.org
- DNS ASK cd#.##scordapp.com
- '%WINDIR%\syswow64\explorer.exe'