Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Steam' = '%APPDATA%\NVIDIA\dllhost.exe'
- %WINDIR%\temp\swift_fix.exe
- %APPDATA%\nvidia\dllhost.exe
- 'a0####58.xsph.ru':80
- 'yandex.ru':443
- http://a0####58.xsph.ru/swift_fix.exe
- 'yandex.ru':443
- DNS ASK a0####58.xsph.ru
- DNS ASK yandex.ru
- '%WINDIR%\temp\swift_fix.exe'
- '<SYSTEM32>\cmd.exe' /C start %WINDIR%\Temp\swift_fix.exe