Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsHost' = '%APPDATA%\WinHost\svchost.exe'
- <SYSTEM32>\wbem\Performance\WmiApRpl_new.ini
- %APPDATA%\WinHost\svchost.exe
- 'ar###haj.com':80
- 'no###ookkids.in':80
- 'ge##sb.com':80
- 'en###deyu.com':80
- 'sl##rs.com':80
- ar###haj.com/entrez/gabel.php
- no###ookkids.in/entrez/gabel.php
- ge##sb.com/entrez/gabel.php
- en###deyu.com/entrez/gabel.php
- sl##rs.com/entrez/gabel.php
- DNS ASK no####ok-sleeve.biz
- DNS ASK no####ok-blog.asia
- DNS ASK do####notebook.biz
- DNS ASK ge####gcorny.biz
- DNS ASK co###pickup.biz
- DNS ASK sl##rs.com
- DNS ASK en###deyu.com
- DNS ASK ge##sb.com
- DNS ASK no###ookkids.in
- DNS ASK ar###haj.com
- ClassName: 'Indicator' WindowName: ''