Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'DesertSetup.exe' = '<Полный путь к вирусу> /r'
- C:\Downloads\DesertSetup.exe.partial
- 'tn##.tmsrv.com':80
- tn##.tmsrv.com/o=64/d=d88267395c91af18841b34116e141ebd00000000000000000000000000000000b7acb365cf080c547c59483f27e061447475636f77735f636f6d00000000000055534420202000000019991073920826/r/release/anarchy/60m_d_v1/DesertSetup.exe
- DNS ASK tn##.tmsrv.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''