Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'f2dbaec52ed6831b30e1a6a1858c56fa' = '"%HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchostt.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'f2dbaec52ed6831b30e1a6a1858c56fa' = '"%HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchostt.exe" ..'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchostt.exe' = '%HOMEPATH%\AppDat...
- '%HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchostt.exe'
- '%HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchostt-t.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchostt.exe" "Svchostt.exe" ENABLE
- '<SYSTEM32>\schtasks.exe' /create /TN "Windows\Windows Fixer RGJLK " /XML "%HOMEPATH%\AppData\Local\xi4zQ0ZBTS\x"
- %HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchostt-t.exe
- %HOMEPATH%\AppData\Local\xi4zQ0ZBTS\XML.txt
- %HOMEPATH%\AppData\Local\xi4zQ0ZBTS\x
- %HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchost.Text
- %HOMEPATH%\AppData\Local\xi4zQ0ZBTS\MCconfig.dll
- %HOMEPATH%\AppData\Local\xi4zQ0ZBTS\WindowsCodecsRaw.txt
- %HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchost.Text в %HOMEPATH%\AppData\Local\xi4zQ0ZBTS\Svchostt.exe
- 'localhost':1
- 'dn#.##ngspy.info':1
- DNS ASK dn#.##ngspy.info