Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\nCfwhhnVNSV.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\nCfwhhnVNSV.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\UnwILpvOHU\nCfwhhnVNSV.dll"'
- 'nCfwhhnVNSV.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\UnwILpvOHU\nCfwhhnVNSV.dll"
- '<SYSTEM32>\regsvr32.exe' /S ..\soci1.ocx
- '<SYSTEM32>\regsvr32.exe' /S ..\soci2.ocx
- '<SYSTEM32>\regsvr32.exe' /S ..\soci3.ocx
- '<SYSTEM32>\regsvr32.exe' /S ..\soci4.ocx
- %HOMEPATH%\soci3.ocx
- %HOMEPATH%\soci3.ocx в <SYSTEM32>\unwilpvohu\ncfwhhnvnsv.dll
- 'fi###.##m.gunadarma.ac.id':443
- 'x1.#.lencr.org':80
- 'eb###a.co.za':80
- 'oc##.#tartssl.com':80
- '3d####ioa.com.br':80
- 'bo###mart.co.za':80
- http://x1.#.lencr.org/
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- http://3d####ioa.com.br/files/1ubPAB/
- 'fi###.##m.gunadarma.ac.id':443
- DNS ASK fi###.##m.gunadarma.ac.id
- DNS ASK x1.#.lencr.org
- DNS ASK eb###a.co.za
- DNS ASK oc##.#tartssl.com
- DNS ASK 3d####ioa.com.br
- DNS ASK bo###mart.co.za
- '<SYSTEM32>\regsvr32.exe' /S ..\soci1.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /S ..\soci2.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /S ..\soci3.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /S ..\soci4.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\UnwILpvOHU\nCfwhhnVNSV.dll"