Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\NetTcpPortSharingSys] 'Start' = '00000002'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\svchost.exe' -k netsvcs
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\Com\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- <SYSTEM32>\Com\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'ny###rta.com':80
- ny###rta.com/ZqFcoWhcD8Nh1dS2GK26pwYd/8F/38BLIme00fYky/xQNpdGnpyuPLJgNHyW-4Qcyxmkk8xeiopU5eE3mPsCVw4zylg7hVg0KJPidjVUPoM.gif
- ny###rta.com/HMZHeYAmwMiWMFxqgn84.1zhQg8UneuUXGEgeQ0FVGbztc9U7Hp/ZwS3zzFxg08jQzWCO9D2wPBe5EmRGlF1F.lRBJkb1ij.UknHbuV3BBHJ73P21PpuFYt6DSo1AB9azh6TucM-v.gif
- DNS ASK ny###rta.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'If execution is allowed'