Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SmartIndex' = '<Полный путь к файлу>'
- [<HKLM>\SYSTEM\ControlSet001\Services\NPF] 'ImagePath' = 'system32\drivers\NPF.sys'
- <DRIVERS>\npf.sys
- <SYSTEM32>\wpcap.dll
- <SYSTEM32>\Packet.dll
- '12#.#48.230.209':80
- 'localhost':1060
- '11#.#72.162.38':80
- 'localhost':1054
- '12#.#78.14.62':80
- 'localhost':1057
- '77.#39.3.11':80
- 'localhost':1069
- '58.##7.239.34':80
- 'localhost':1063
- '12#.#48.96.66':80
- 'localhost':1066
- '87.##6.12.13':80
- 'localhost':1042
- '77.#39.4.42':80
- 'localhost':1036
- '72.##0.200.42':80
- 'localhost':1039
- '46.##1.198.122':80
- 'localhost':1051
- '21#.#92.20.224':80
- 'localhost':1045
- '21#.70.89.5':80
- 'localhost':1048