Техническая информация
- %WINDIR%\tasks\deviceready.job
- <SYSTEM32>\tasks\deviceready
- [<HKLM>\System\CurrentControlSet\Services\Remorseful Friendship] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Remorseful Friendship] 'ImagePath' = '%APPDATA%\Remorseful Friendship\Remorseful Friendship.exe'
- 'Remorseful Friendship' %APPDATA%\Remorseful Friendship\Remorseful Friendship.exe
- %ALLUSERSPROFILE%\{dca5317b-9fd2-7057-dca5-5317b9fdc5ee}\<Имя файла>.exe
- %ALLUSERSPROFILE%\{dca5317b-9fd2-7057-dca5-5317b9fdc5ee}\<Имя файла>.dat
- %APPDATA%\remorseful friendship\remorseful friendship.exe
- %APPDATA%\remorseful friendship\fba00.dat
- 'al####el-pro.com':80
- 'ge####ltiple.link':80
- http://ge####ltiple.link/?q=#####################################################################################################################################################################...
- DNS ASK ge####ltiple.link
- DNS ASK al####el-pro.com
- '%APPDATA%\remorseful friendship\remorseful friendship.exe'