Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'c84c7bd5e9583983454b90fec3f9f33a' = '"%TEMP%\FlashPlayerPlugin.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'c84c7bd5e9583983454b90fec3f9f33a' = '"%TEMP%\FlashPlayerPlugin.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\c84c7bd5e9583983454b90fec3f9f33a.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\FlashPlayerPlugin.exe' = '%TEMP%\FlashPlayerPlugin.exe:*:Enabled:FlashPlayerPlugin.exe'
- %TEMP%\FlashPlayerPlugin.exe
- <SYSTEM32>\netsh.exe firewall add allowedprogram "%TEMP%\FlashPlayerPlugin.exe" "FlashPlayerPlugin.exe" ENABLE
- %TEMP%\FlashPlayerPlugin.exe
- 'fl######date.servehttp.com':1177
- DNS ASK FL######DATE.SERVEHTTP.COM
- ClassName: 'Indicator' WindowName: ''