Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe,"%LOCALAPPDATA%\Detrimantor\experto.exe",'
- dantorei.exe
- %ALLUSERSPROFILE%\dantorei.exe
- %ALLUSERSPROFILE%\tut.txt
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<Имя файла>.exe.log
- %LOCALAPPDATA%\detrimantor\experto.exe
- %TEMP%\dantorei.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\dantorei.exe.log
- 'co##oso.com':80
- http://www.co##oso.com/PostAccepter.aspx
- DNS ASK co##oso.com
- DNS ASK tr#####edia555.ddns.net
- '%ALLUSERSPROFILE%\dantorei.exe'
- '%TEMP%\dantorei.exe'
- '%WINDIR%\syswow64\notepad.exe' %ALLUSERSPROFILE%\TUT.txt