Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\b6888f22f9801c5a8745383a22c4f225.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\syscmed.exe' = '%TEMP%\syscmed.exe:*:Enabled:syscmed.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\syscmed.exe" "syscmed.exe" ENABLE
- '%TEMP%\syscmed.exe'
- %TEMP%\syscmed.exe
- 'zi####25.hopto.org':1177
- DNS ASK zi####25.hopto.org