Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'FileRescue' = 'C:\ZeroLocker\ZeroRescue.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\desktop.ini.encrypt
- C:\ZeroLocker\temp.dat
- C:\ZeroLocker\address.dat
- C:\ZeroLocker\ZeroRescue.exe
- '5.###.171.47':80
- 'wp#d':80
- 5.###.171.47/zConfig/178102
- 5.###.171.47/zImprimer/3547962209-jFctyAJxJczvStV7wP5J-1BiXC9sJA1q3kfCQqLs1ibPqkdapRtPZX5
- wp#d/wpad.dat
- 5.###.171.47/patriote/sansviolence
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'