Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ac914ea' = '%APPDATA%\ac914ea.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ac914e' = 'C:\ac914ea\ac914ea.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\ac914ea.exe
- Компонент восстановления системы (SR)
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet
- '<SYSTEM32>\svchost.exe' netsvcs
- '%WINDIR%\explorer.exe'
- <SYSTEM32>\svchost.exe
- %APPDATA%\ac914ea.exe
- C:\ac914ea\ac914ea.exe
- 'do####canajoker.com':80
- http://do####canajoker.com/399p93hx6kbqp
- http://do####canajoker.com/t6u1kh0y41h9e
- http://do####canajoker.com/9mb0o14r97599lf
- http://do####canajoker.com/bb4b53r3rbz7lih
- http://do####canajoker.com/0u2y9ya2b8
- http://do####canajoker.com/43cxg1n9m4p
- http://do####canajoker.com/skfkx6ouytaju
- http://do####canajoker.com/sp8l7c125wtxe
- http://do####canajoker.com/4h3qz397bnd6
- http://do####canajoker.com/z2plsz4hpwu0hgv
- http://do####canajoker.com/2l1l08oj384a2
- http://do####canajoker.com/uwccmbfmhbwplq9
- http://do####canajoker.com/kdfmrqbj7to2a
- http://do####canajoker.com/7tobxcfuljv
- http://do####canajoker.com/57emubswcy6s
- DNS ASK do####canajoker.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: ''