Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SmartIndex' = '<Полный путь к вирусу>'
- [<HKLM>\SYSTEM\ControlSet001\Services\NPF] 'ImagePath' = 'system32\drivers\NPF.sys'
- <DRIVERS>\npf.sys
- <SYSTEM32>\wpcap.dll
- <SYSTEM32>\Packet.dll
- 'localhost':1052
- '21#.#92.20.224':80
- 'localhost':1049
- '46.##1.198.122':80
- 'localhost':1058
- '12#.#48.230.209':80
- 'localhost':1055
- '12#.#78.14.62':80
- 'localhost':1040
- '87.##6.12.13':80
- 'localhost':1037
- '72.##0.200.42':80
- 'localhost':1046
- '21#.70.89.5':80
- 'localhost':1043
- '77.#39.4.42':80