Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\eSafeSvc] 'Start' = '00000002'
- '%ALLUSERSPROFILE%\Application Data\eSafe\<Имя вируса>.exe'
- '%ALLUSERSPROFILE%\Application Data\eSafe\<Имя вируса>.exe' -run
- ClassName: '' WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: '' WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass' WindowName: ''
- ClassName: '' WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'GBDYLLO' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: 'FilemonClass' WindowName: ''
- ClassName: 'pediy06' WindowName: ''
- %ALLUSERSPROFILE%\Application Data\eSafe\<Имя вируса>.exe
- 'ad#.#oft365.com':80
- 'xa.###gcloud.com':80
- http://ad#.#oft365.com/gdp/softupdate?pt###############################################################################################
- http://xa.###gcloud.com/v4/sof-newgdp/<Служебное имя>X<Служебное имя>XIDEXHardXDrive_11000000000000000001?ac#####################################################################################...
- DNS ASK ad#.#oft365.com
- DNS ASK xa.###gcloud.com
- ClassName: '18467-41' WindowName: ''