Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SonyAgent' = '<Полный путь к вирусу>'
- \Device\HarddiskVolume1\Boot\BCD
- \Device\HarddiskVolume1\Boot\BCD.LOG
- <Полный путь к вирусу>
- 'localhost':49200
- '92.##.137.17':80
- '21#.#84.247.70':80
- '88.##4.192.173':80
- 'localhost':49203
- '10#.#7.117.16':80
- 'localhost':49191
- 'localhost':49194
- 'localhost':49197
- '10#.#22.23.67':80
- 'localhost':49206
- '77.##2.212.40':80
- 'localhost':49215
- '17#.#4.207.54':80
- '18#.#54.163.37':80
- '5.##5.75.42':80
- 'localhost':49209
- '81.##0.246.11':80
- '5.##5.15.62':80
- '61.#7.94.4':80
- 'localhost':49212
- '5.#.3.190':80
- 'localhost':49167
- '17#.#51.3.78':80
- '46.##.240.29':80
- '46.##9.205.81':80
- 'localhost':49170
- '10#.191.5.5':80
- 'localhost':49158
- 'localhost':49161
- 'localhost':49164
- '85.##8.81.26':80
- 'localhost':49173
- '18#.#31.227.24':80
- 'localhost':49182
- 'localhost':49185
- 'localhost':49188
- '15#.#24.118.75':80
- 'localhost':49176
- '17#.#50.196.204':80
- '89.##.116.23':80
- '17#.#50.185.73':80
- 'localhost':49179
- 18#.#54.163.37/start.htm
- 77.##2.212.40/setup.htm
- 17#.#4.207.54/login.htm
- 5.##5.75.42/file.htm