Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'X4C8pLdr8HWbihj' = '%APPDATA%\AudioTreiber_x64.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'X4C8pLdr8HWbihj' = '%APPDATA%\AudioTreiber_x64.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Fupdate' = '%APPDATA%\svhost.exe'
- скрытых файлов
- '%APPDATA%\AudioTreiber_x64.exe'
- '%TEMP%\999999.exe'
- '%APPDATA%\svhost.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\KGuPF.bat
- %TEMP%\999999.exe
- %APPDATA%\AudioTreiber_x64.exe
- %APPDATA%\svhost.exe
- %TEMP%\KGuPF.bat
- %APPDATA%\svhost.exe
- '74.##5.232.51':80
- 'ta####i-st0re.net':80
- 'wp#d':80
- ta####i-st0re.net/qwe/333/gate.php?hw###################################################################################
- wp#d/wpad.dat
- DNS ASK google.com
- DNS ASK ta####i-st0re.net
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'