Техническая информация
- [HKLM\System\CurrentControlSet\Services\Com+ System Service] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Com+ System Service] 'ImagePath' = '<SYSTEM32>\svchost.exe -k svccom'
- [HKLM\SYSTEM\CurrentControlSet\Services\Com+ System Service\Parameters] 'ServiceDll' = '<SYSTEM32>\comaddon.dll'
- 'Com+ System Service' <SYSTEM32>\svchost.exe -k svccom
- %TEMP%\comaddon.dll
- <SYSTEM32>\comaddon.dll
- <SYSTEM32>\ndriver.ini
- <SYSTEM32>\dx3.txt
- %TEMP%\comaddon.dll
- <SYSTEM32>\dx3.txt
- '34.##9.100.209':443
- 'ft#.##ethost8.com':21
- '34.##9.100.209':443
- 'ft#.##ethost8.com':21
- DNS ASK ft#.##ethost8.com
- '<SYSTEM32>\svchost.exe' -k svccom
- '<SYSTEM32>\cmd.exe' /C systeminfo > <SYSTEM32>\DX3.txt (со скрытым окном)
- '<SYSTEM32>\systeminfo.exe'