Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WLS' = '%WINDIR%\sysWOW322\ServiceDownLoader.exe'
- %WINDIR%\sysWOW322\ServiceMain.dll
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\UEWNTWLX\ServiceMain32[1].dll
- %WINDIR%\sysWOW322\ServiceInstall.dll
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\23BUYPX5\ServiceInstall32[1].dll
- %WINDIR%\sysWOW322\ServiceDownLoaderH.dll
- %APPDATA%\Roaming\Microsoft\Protect\S-1-5-21-2832440558-3064306045-1455513625-1000\2bfd0c44-03f8-4d9d-b919-e5a6ca74a621
- %WINDIR%\sysWOW322\ServiceDownLoader.ini
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\YIF7DGLM\ServiceDownLoaderH32[1].dll
- %APPDATA%\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2832440558-3064306045-1455513625-1000\3310a4fa6cb9c60504498d7eea986fc2_97c09787-6498-4b10-8f65-9471d842c55e
- %WINDIR%\sysWOW322\ServiceDownLoader.ini
- '15#.#54.133.171':80
- http://15#.#54.133.171/In4Installer/PatchVersion/File/ServiceInstall32.dll
- http://15#.#54.133.171/In4Installer/PatchVersion/ServiceMain32.dll
- http://15#.#54.133.171/In4Installer/PatchVersion/ServiceDownLoaderH32.dll