Техническая информация
- %WINDIR%\tasks\healthtracker.job
- <SYSTEM32>\tasks\healthtracker
- [<HKLM>\System\CurrentControlSet\Services\Calculated Drove] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Calculated Drove] 'ImagePath' = '%APPDATA%\Calculated Drove\Calculated Drove.exe'
- 'Calculated Drove' %APPDATA%\Calculated Drove\Calculated Drove.exe
- %ALLUSERSPROFILE%\{17dd130f-7f8a-9224-17dd-d130f7f84c3d}\<Имя файла>.exe
- %APPDATA%\calculated drove\calculated drove.exe
- %ALLUSERSPROFILE%\{17dd130f-7f8a-9224-17dd-d130f7f84c3d}\<Имя файла>.dat
- %APPDATA%\calculated drove\fba00.dat
- 'ge####ltiple.link':80
- 'al####el-pro.com':80
- http://ge####ltiple.link/?q=#####################################################################################################################################################################...
- DNS ASK ge####ltiple.link
- DNS ASK al####el-pro.com
- '%APPDATA%\calculated drove\calculated drove.exe'