Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'z9a4n9yi5q9' = '%HOMEPATH%\z9a4n9yi5q9\86989.vbs'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe' = '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe:*:Enabled:RegSvcs.exe'
- '%HOMEPATH%\z9a4n9yi5q9\aTvDLHHckm.com' rwINYdTYB
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe" "RegSvcs.exe" ENABLE
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %HOMEPATH%\z9a4n9yi5q9\78181.cmd
- %HOMEPATH%\z9a4n9yi5q9\86989.vbs
- %HOMEPATH%\z9a4n9yi5q9\run.vbs
- %HOMEPATH%\z9a4n9yi5q9\JwXsQ.JWS
- %HOMEPATH%\z9a4n9yi5q9\dOlgdxLujoA.SHT
- %HOMEPATH%\z9a4n9yi5q9\aTvDLHHckm.com
- %HOMEPATH%\z9a4n9yi5q9\rwINYdTYB
- %HOMEPATH%\z9a4n9yi5q9\JwXsQ.JWS
- %HOMEPATH%\z9a4n9yi5q9\86989.vbs
- %HOMEPATH%\z9a4n9yi5q9\78181.cmd
- %HOMEPATH%\z9a4n9yi5q9\dOlgdxLujoA.SHT
- %HOMEPATH%\z9a4n9yi5q9\aTvDLHHckm.com
- %HOMEPATH%\z9a4n9yi5q9\rwINYdTYB
- 'ew####n.no-ip.org':16540
- DNS ASK ew####n.no-ip.org
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'