Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Dllhost' = '<SYSTEM32>\dIIhost.exe'
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="Kekeo Messenger" dir=out program="%WINDIR%\explorer.exe" action=allow
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="Kekeo Messenger" dir=in program="%WINDIR%\explorer.exe" action=allow
- '<SYSTEM32>\cmd.exe' /c ""<SYSTEM32>\systam.bat" "
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram program = "%WINDIR%" mode = ENABLE
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\systam.bat
- <SYSTEM32>\zilb.dll
- из <Полный путь к файлу> в <SYSTEM32>\dIIhost.exe
- 'ja##han.ml':23456
- DNS ASK ja##han.ml