Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'LazRusGard.exe' = '%ProgramFiles%\LazRusGard\LazRusGard.exe'
- '%ProgramFiles%\LazRusGard\LazRusGard.exe' (загружен из сети Интернет)
- '<SYSTEM32>\cmd.exe' /c <Текущая директория>\$2s3d.bat
- '<SYSTEM32>\cmd.exe' schtasks /create /sc onlogon /tn "Windows LazRusGard Installer 1.1" /tr "\"%ProgramFiles%\LazRusGard\LazRusGard.exe"\" /rl highest
- <Текущая директория>\$2s3d.bat
- %ProgramFiles%\LazRusGard\LazRusGard.exe
- %ProgramFiles%\LazRusGard\ar.dat
- 'ju##ip.com':80
- 'on####three.co.kr':80
- http://on####three.co.kr/old4year/www/check/check.php?m=##################
- http://ju##ip.com/t_ptr/awrite.php?pt##
- http://on####three.co.kr/old4year/www/upload2/LazRusGard.exe
- http://on####three.co.kr/old4year/www//troute/earse_easy.php
- http://on####three.co.kr/old4year/www/troute/trout_up.php
- DNS ASK ju##ip.com
- DNS ASK on####three.co.kr