Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ac914ea' = '%APPDATA%\ac914ea.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ac914e' = 'C:\ac914ea\ac914ea.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\ac914ea.exe
- Компонент восстановления системы (SR)
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet
- '<SYSTEM32>\svchost.exe' netsvcs
- '%WINDIR%\explorer.exe'
- <SYSTEM32>\svchost.exe
- %APPDATA%\ac914ea.exe
- C:\ac914ea\ac914ea.exe
- 'do####canajoker.com':80
- http://do####canajoker.com/wrde1kcatwlzopo
- http://do####canajoker.com/a0amz66deiyca8
- http://do####canajoker.com/9539hg5v6squ7dz
- http://do####canajoker.com/pdzu28h1mi03
- http://do####canajoker.com/wt9r28gorl
- http://do####canajoker.com/z8b3lt0500yht
- http://do####canajoker.com/kx8p9z8i02us
- http://do####canajoker.com/h7h2g58h32r
- http://do####canajoker.com/fs6kzynbfajp1
- http://do####canajoker.com/zuurfiwfntsn
- http://do####canajoker.com/bh3elm97u7lw51
- http://do####canajoker.com/e2sdoei932xyg
- DNS ASK do####canajoker.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''