Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{CAUS9Z2Q-254570-JHAZ9F-JHAZ9F2X99}' = '"%APPDATA%\svchost.exe" ...'
- %HOMEPATH%\Start Menu\Programs\Startup\{CAUS9Z2Q-254570-JHAZ9F-JHAZ9F2X99}.exe
- скрытых файлов
- '%APPDATA%\svchost.exe'
- %APPDATA%\svchost.exe
- %HOMEPATH%\Start Menu\Programs\Startup\{CAUS9Z2Q-254570-JHAZ9F-JHAZ9F2X99}.exe
- %APPDATA%\svchost.exe
- 'ba####ack.sytes.net':5552
- 'localhost':5552
- DNS ASK ba####ack.sytes.net