Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'e762428b721a1de0e50cb93c91ca629c' = '"C:\ProgramData\System32.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'e762428b721a1de0e50cb93c91ca629c' = '"C:\ProgramData\System32.exe" ..'
- 'C:\ProgramData\System32.exe'
- '<LS_APPDATA>xiWGFuSDEO.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "C:\ProgramData\System32.exe" "System32.exe" ENABLE
- '<SYSTEM32>\DllHost.exe' /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}
- %APPDATA%\Roaming\Microsoft\Windows\Recent\AppData.lnk
- C:\ProgramData\System32.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e762428b721a1de0e50cb93c91ca629c.exe
- %APPDATA%\Roaming\Microsoft\Windows\Recent\LocaloMPqlVesEc.lnk
- <LS_APPDATA>xiWGFuSDEO.exe
- <LS_APPDATA>oMPqlVesEc.jpg
- <SYSTEM32>\Tasks\Microsoft\Windows Defender\MP Scheduled Scan
- 'an#####acker.no-ip.biz':1177
- DNS ASK dn#.##ftncsi.com
- DNS ASK an#####acker.no-ip.biz
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''