Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'LAN Service' = '%PROGRAM_FILES%\LAN Service\lansv.exe'
- '%TEMP%\peverify.exe' -woohoo 3184 %TEMP%\chrome.exe
- '%TEMP%\chrome.exe'
- '%TEMP%\peverify.exe' -woohoo 2928 %TEMP%\chrome.exe
- '<SYSTEM32>\schtasks.exe' /Create /TN "Update\Google Update" /XML "%TEMP%\aUUUUU.xml"
- '<SYSTEM32>\schtasks.exe' /Create /TN "Update\Google Update" /XML "%TEMP%\ayyyyy.xml"
- '<SYSTEM32>\schtasks.exe' /Create /TN "Update\Google Update" /XML "%TEMP%\a00000.xml"
- %PROGRAM_FILES%\LAN Service\lansv.exe
- %TEMP%\ayyyyy.xml
- %TEMP%\aUUUUU.xml
- %APPDATA%\23EF5514-3059-436F-A4A7-4CEFAAB20EB1\run.dat
- %TEMP%\chrome.exe
- %TEMP%\a00000.xml
- %TEMP%\peverify.exe
- %TEMP%\chrome.exe
- %TEMP%\ayyyyy.xml
- %TEMP%\a00000.xml
- 'la###hare.net':80
- 'ru#######ckupserver.dnsfor.me':4545
- 'ru######ainserver.dnsfor.me':4545
- 'wp#d':80
- wp#d/wpad.dat
- la###hare.net/NanoStats/NanoStats.php
- DNS ASK la###hare.net
- DNS ASK ru#######ckupserver.dnsfor.me
- DNS ASK ru######ainserver.dnsfor.me
- DNS ASK wp#d