Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\Desktop.exe' = '%TEMP%\Desktop.exe:*:Enabled:Desktop.exe'
- '%TEMP%\System.exe'
- '%TEMP%\Desktop.exe'
- '%TEMP%\twinmotion_crack_by_305andDarkScreem.exe'
- '%TEMP%\AutoPlay.exe'
- '<SYSTEM32>\msiexec.exe' -Embedding 4ECE4DC1C18C0FAD2EBBA8F1B2B6ADDF C
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\Desktop.exe" "Desktop.exe" ENABLE
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\cmd.exe' /k powershell REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v EnableLUA /t REG_SZ /d %TEMP%\System.exe
- %TEMP%\MSI5.tmp
- %TEMP%\MSI4.tmp
- %TEMP%\MSI3.tmp
- %TEMP%\MSI6.tmp
- %TEMP%\MSI360ce.LOG
- %TEMP%\MSI8.tmp
- %TEMP%\MSI7.tmp
- %APPDATA%\3O5\Twinmotion 2018 Crack by 3O5 2.5.9\install\decoder.dll
- %TEMP%\AutoPlay.exe
- %TEMP%\twinmotion_crack_by_305andDarkScreem.exe
- %APPDATA%\3O5\Twinmotion 2018 Crack by 3O5 2.5.9\install\262829B\twinmotion2_crack.msi
- %TEMP%\MSI2.tmp
- %TEMP%\Desktop.exe
- %TEMP%\System.exe
- %TEMP%\MSI5.tmp
- %TEMP%\MSI6.tmp
- %TEMP%\MSI7.tmp
- %TEMP%\MSI2.tmp
- %TEMP%\MSI3.tmp
- %TEMP%\MSI4.tmp
- 'ka####.selfip.net':49123
- DNS ASK ka####.selfip.net