Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\svchost64.lnk
- '<SYSTEM32>\rundll32.exe' "%TEMP%\89a5f0e88c24.dll",StartShell StartShell_A
- '<SYSTEM32>\rundll32.exe' "%TEMP%\89a5f0e88c24.dll",StartShell
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1400' = '00000000'
- %TEMP%\89a5f0e88c24.dll
- %TEMP%\svchost64.cnm
- %TEMP%\RCX1.tmp
- %TEMP%\26362_10212.zip
- %TEMP%\26362_10212.dll
- %TEMP%\26362_10212.dll
- %TEMP%\26362_10212.zip
- %TEMP%\RCX1.tmp в %TEMP%\26362_10212.dll
- 'gi###eapple.com':80
- gi###eapple.com/kernel/usa.txt
- DNS ASK gi###eapple.com