Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '0Z' = '%ALLUSERSPROFILE%\Start Menu\Programs\mot.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\KifnjjoO5u.eu.url
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
- %APPDATA%\Imminent\Logs\11-11-2017
- %APPDATA%\Imminent\Monitoring\network.dat
- %APPDATA%\Imminent\Monitoring\system.dat
- %TEMP%\fD.4h
- %APPDATA%\KifnjjoO5u\KifnjjoO5u.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\mot.exe
- %TEMP%\aut1.tmp
- %TEMP%\aut1.tmp
- 'sh####m.duckdns.org':1800
- DNS ASK sh####m.duckdns.org