Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\DcomLaunchSys] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\Com\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- <SYSTEM32>\Com\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- из <Полный путь к вирусу> в <Полный путь к вирусу>1
- 'fi#####alnewsonline.pw':80
- '18#.#0.56.59':443
- fi#####alnewsonline.pw/kNqXehYhWua2VsLccQBqblBziBU4SLpF311ypR2BiYGDdnhrpYSC-JrXhtaZx5mElV-f3pIlUNBJcH7U8L-ao/4gOo4OfEe.WpyC6E7rCEXLl4NDSGTBhSTESkW7vvgPC9Nb1CD82.html
- fi#####alnewsonline.pw/vxVXxAknH9/Di/tNE/ZmnAM.XYo3e5S1X4yrBfPP-NI6un2UiKKnMzyaLBM.h.cgi?P-#################################################
- fi#####alnewsonline.pw/xByxMLPBFmkVlvhlbM1tbEnnI/y/F3T8wWGUfPPTs8lc.Wn8bmm/t8YHjXsN9h5wFkzHcPbfqY9evwSBh-G.php?rh#######################################################################################
- DNS ASK fi#####alnewsonline.pw
- ClassName: 'Shell_TrayWnd' WindowName: ''