Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\dhwgdcdi.lnk
- <SYSTEM32>\tasks\opera scheduled autoupdate 2824836542
- %APPDATA%\microsoft\windows\dhwgdcdi\rcivvcsg.exe
- %APPDATA%\microsoft\windows\dhwgdcdi\rcivvcsg.exe
- 'ms###csi.com':80
- 'wi####urlife.com':80
- 'wi####urlife.com':443
- http://www.ms###csi.com/ncsi.txt
- http://wi####urlife.com/
- 'wi####urlife.com':443
- DNS ASK my####dempty.com
- DNS ASK qi###mpty.com
- DNS ASK wi####urlife.com
- DNS ASK st##to.de
- DNS ASK cl###empydn.com
- '%APPDATA%\microsoft\windows\dhwgdcdi\rcivvcsg.exe'
- '%APPDATA%\microsoft\windows\dhwgdcdi\rcivvcsg.exe' ' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {5467FEE8-9D9B-49ED-9D6C-48A32B107CF3} S-1-5-21-2594934582-3011428313-3661137593-1000:uswcqcmlmaqf\user:Interactive:[1]