Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '18694cc4-d3be-a5eb-752b-38981c4729d1' = '%LOCALAPPDATA%\Microsoft\473ba147-9c1b-a45a-7a66-782a87a904db\9f9a21d7-e65d-4c8d-9ef3-c3a04f8b65e8...
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\dllhost.exe
- <SYSTEM32>\dllhost.exe
- %LOCALAPPDATA%\microsoft\ccfe26be-5cb5-a4f7-66f4-a224376ca639\14829e10-b1fa-a5e9-68d9-52b3f7dd2439
- %LOCALAPPDATA%\microsoft\ccfe26be-5cb5-a4f7-66f4-a224376ca639\f5aa2a8a-8682-a233-7aae-dc86a12b62cf
- %LOCALAPPDATA%\microsoft\473ba147-9c1b-a45a-7a66-782a87a904db\9f9a21d7-e65d-4c8d-9ef3-c3a04f8b65e8.exe
- 'ku###toop.com':80
- http://ku###toop.com/gate/
- DNS ASK gi###sard.net
- DNS ASK ku###toop.com
- '%LOCALAPPDATA%\microsoft\473ba147-9c1b-a45a-7a66-782a87a904db\9f9a21d7-e65d-4c8d-9ef3-c3a04f8b65e8.exe'
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\dllhost.exe'
- '<SYSTEM32>\dllhost.exe'