Техническая информация
- '%WINDIR%\installer\msic509.tmp' /DontWait C:/Windows/SysWOW64/rundll32.exe %APPDATA%\vierm_soft_x64.dll, GetDeepDVCState
- %APPDATA%\vierm_soft_x64.dll
- '19#.#4.156.91':80
- 'gr###unka.com':8041
- 'ti###nin.com':8041
- http://19#.#4.156.91/dsa.msi
- 'gr###unka.com':8041
- DNS ASK gr###unka.com
- DNS ASK ti###nin.com
- '%WINDIR%\syswow64\rundll32.exe' %APPDATA%\vierm_soft_x64.dll, GetDeepDVCState
- '<SYSTEM32>\rundll32.exe' %APPDATA%\vierm_soft_x64.dll, GetDeepDVCState