Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'directvaccine' = '%PROGRAM_FILES%\directvaccine\directvaccineu.exe /8L'
- '%TEMP%\directvaccinesetup_jane.exe'
- %TEMP%\directvaccinesetup_jane.exe
- %TEMP%\filesST.zip
- 'pl####rive.co.kr':80
- 'di####vaccine.co.kr':80
- 'localhost':1037
- di####vaccine.co.kr/value.php?st##########################################################################
- di####vaccine.co.kr/version/version
- di####vaccine.co.kr/etc/yak_app.htm
- pl####rive.co.kr/APP/ck_setup.php?m=######################
- DNS ASK up####.#irectvaccine.co.kr
- DNS ASK pl####rive.co.kr
- DNS ASK di####vaccine.co.kr
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''