Техническая информация
- [HKLM\System\CurrentControlSet\Services\Rsmuth kfrfvazk] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rsmuth kfrfvazk] 'ImagePath' = '%WINDIR%\Evyruf.exe -auto'
- [HKLM\System\CurrentControlSet\Services\Qogxog Jphxp] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Qogxog Jphxp] 'ImagePath' = '<SYSTEM32>\Hnevm.exe -auto'
- 'Rsmuth kfrfvazk' %WINDIR%\Evyruf.exe -auto
- 'Qogxog Jphxp' <SYSTEM32>\Hnevm.exe -auto
- C:\input.txt
- %WINDIR%\syswow64\ini.ini
- %WINDIR%\evyruf.exe
- %WINDIR%\smsc.exe
- %WINDIR%\syswow64\hnevm.exe
- %WINDIR%\evyruf.exe
- C:\input.txt
- C:\input.txt
- '38.##.220.159':8001
- 'no##b.xyz':8080
- 'no##b.xyz':80
- 'ta##ao.com':80
- 'ta##ao.com':443
- http://www.ta##ao.com/help/getip.php
- '38.##.220.159':8001
- 'ta##ao.com':443
- DNS ASK no##b.xyz
- DNS ASK ta##ao.com
- '%WINDIR%\evyruf.exe' -auto
- '%WINDIR%\evyruf.exe' -acsi
- '%WINDIR%\smsc.exe'
- '%WINDIR%\syswow64\hnevm.exe' -auto
- '%WINDIR%\syswow64\hnevm.exe' -acsi
- '%WINDIR%\syswow64\cmd.exe' /c start %WINDIR%\smsc.exe' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c start %WINDIR%\smsc.exe