Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WLIDSVC' = '"%ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\WLIDSVC.exe"'
- '%ALLUSERSPROFILE%\Application Data\LBAEvent.exe' /C reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v WLIDSVC /t REG_SZ /d "\"%ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\WLIDSVC.exe"\""
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v WLIDSVC /t REG_SZ /d "\"%ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\WLIDSVC.exe"\""
- %ALLUSERSPROFILE%\Application Data\Microsoft\Network\Perh0.tmp
- %ALLUSERSPROFILE%\Application Data\Microsoft\Network\conhost.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\WLIDSVC.exe
- %ALLUSERSPROFILE%\Application Data\LBAEvent.exe
- 'www.am####-movie.com':80
- http://www.am####-movie.com/cli/index.php
- DNS ASK www.am####-movie.com
- ClassName: 'Indicator' WindowName: ''