Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Microsoft Corporation.exe
- <Имя диска съемного носителя>:\Notepad.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\InstallDir\explorer.exe' = '%TEMP%\InstallDir\explorer.exe:*:En...
- '%TEMP%\InstallDir\explorer.exe'
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn StUpdate /tr %HOMEPATH%\Local Settings\Temp/StUpdate.exe
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\InstallDir\explorer.exe" "explorer.exe" ENABLE
- C:\Notepad.exe
- %TEMP%\InstallDir\explorer.exe
- 'de#####ootkali.ddns.net':1177
- DNS ASK de#####ootkali.ddns.net