Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe] 'Debugger' = 'explore.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe] 'Debugger' = 'alge.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ipm' = 'ipm.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'soft' = 'soft.exe'
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\soft02.bat
- '<SYSTEM32>\ftp.exe' -s:<SYSTEM32>\cftp.txt
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\soft03.bat
- '<SYSTEM32>\cmd.exe' /c soft2.bat
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\soft04.bat
- <SYSTEM32>\soft03.bat
- <SYSTEM32>\soft02.bat
- <SYSTEM32>\cftp.txt
- <Текущая директория>\soft2.bat
- <SYSTEM32>\soft04.bat
- <SYSTEM32>\soft03.bat
- '22#.#14.218.145':21
- 'localhost':1035