Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'b4d05246-9764-4719-8643-eb372d98131f' = '%APPDATA%\elevc\elevc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'b4d05246-9764-4719-8643-eb372d98131f' = '%APPDATA%\elevc\elevc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1806' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1806' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.reg;.vbs;'
- %APPDATA%\elevc\elevc.exe
- 'pu###cdns.in':80
- http://pu###cdns.in/bucs/gateway.php
- DNS ASK pu###cdns.in
- ClassName: 'Indicator' WindowName: ''