Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'TFM0N' = 'c:\4929EU7TP1U9TETV\Agaog.exe'
- C:\4929EU7TP1U9TETV\setting.xml
- из <Полный путь к вирусу> в C:\4929EU7TP1U9TETV\Agaog.exe
- 'us##.#zone.qq.com':80
- '96.##.99.163':805
- '96.##.99.162':8760
- us##.#zone.qq.com/190055271
- us##.#zone.qq.com/125354013
- DNS ASK us##.#zone.qq.com
- ClassName: 'Indicator' WindowName: ''