Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'Microsoft System Service' = 'globalpatch.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft System Service' = 'globalpatch.exe'
- <SYSTEM32>\globalpatch.exe 284 "<Полный путь к вирусу>"
- <SYSTEM32>\globalpatch.exe
- <SYSTEM32>\globalpatch.exe
- 'sp####es.no-ip.org':6667
- DNS ASK sp####es.no-ip.org