Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Syswin32' = '%APPDATA%\framework.exe'
- %APPDATA%\framework.exe
- <SYSTEM32>\netsh.exe advfirewall firewall add rule action=allow profile=any protocol=any enable=yes direction=out name=TeamView program="%TEMP%\teamviewer.exe"
- <SYSTEM32>\netsh.exe advfirewall firewall add rule action=allow profile=any protocol=any enable=yes direction=in name=TeamView program="%TEMP%\teamviewer.exe"
- <SYSTEM32>\netsh.exe advfirewall firewall add rule action=allow profile=any protocol=any enable=yes direction=in name=Win2y2 program="%APPDATA%\framework.exe"
- <SYSTEM32>\notepad.exe
- <SYSTEM32>\netsh.exe advfirewall firewall add rule action=allow profile=any protocol=any enable=yes direction=out name=Win2y2 program="%APPDATA%\framework.exe"
- <SYSTEM32>\notepad.exe
- %TEMP%\aut2.tmp
- %TEMP%\5827676.14600291
- %TEMP%\sevane.tmp
- %APPDATA%\framework.exe
- %TEMP%\aut1.tmp
- %TEMP%\393757.447605931
- %HOMEPATH%\AutoIt3.exe
- %HOMEPATH%\AutoIt3.exe
- %TEMP%\aut2.tmp
- %TEMP%\5827676.14600291
- %TEMP%\aut1.tmp
- %TEMP%\393757.447605931
- 'localhost':1588
- 'xe#####337.sytes.net':1588
- DNS ASK xe#####337.sytes.net
- ClassName: 'Indicator' WindowName: ''