Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'a761c4c33d9b668bb0c32a325fcd216d' = '"%TEMP%\WindApp.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'a761c4c33d9b668bb0c32a325fcd216d' = '"%TEMP%\WindApp.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\a761c4c33d9b668bb0c32a325fcd216d.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\WindApp.exe' = '%TEMP%\WindApp.exe:*:Enabled:WindApp.exe'
- '%TEMP%\WindApp.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\WindApp.exe" "WindApp.exe" ENABLE
- %TEMP%\WindApp.exe
- 'ca#####001.zapto.org':1177
- DNS ASK ca#####001.zapto.org
- ClassName: 'Indicator' WindowName: '(null)'