Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3fec74111e00bdc161140bba51f17f82' = '"%ALLUSERSPROFILE%\svehost.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '3fec74111e00bdc161140bba51f17f82' = '"%ALLUSERSPROFILE%\svehost.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'eMulen' = '<LS_APPDATA>\eMulen.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\3fec74111e00bdc161140bba51f17f82.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ALLUSERSPROFILE%\svehost.exe' = '%ALLUSERSPROFILE%\svehost.exe:*:Enab...
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%ALLUSERSPROFILE%\svehost.exe" "svehost.exe" ENABLE
- %ALLUSERSPROFILE%\svehost.exe
- <LS_APPDATA>\FBAhRhYWRW
- <LS_APPDATA>\eMulen.exe
- 'po###g-i.o-r.kr':7171
- DNS ASK po###g-i.o-r.kr
- '%ALLUSERSPROFILE%\svehost.exe'