Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '7a4c1aa1519c6bee178f8fbf3ccffa01' = '"%TEMP%\Console Window Host.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '7a4c1aa1519c6bee178f8fbf3ccffa01' = '"%TEMP%\Console Window Host.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\7a4c1aa1519c6bee178f8fbf3ccffa01.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\Console Window Host.exe' = '%TEMP%\Console Window Host.exe:*:En...
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\Console Window Host.exe" "Console Window Host.exe" ENABLE
- %TEMP%\is-JDEP5.tmp\Templ.tmp
- %TEMP%\Console Window Host.exe
- %HOMEPATH%\Local Settings\Temps.exe
- %HOMEPATH%\Local Settings\Templ.exe
- %HOMEPATH%\Local Settings\Tempr.exe
- 'xd.##pto.org':27730
- 'xd.##pto.org':27468
- DNS ASK xd.##pto.org
- '%TEMP%\is-JDEP5.tmp\Templ.tmp' /SL5="$200E2,4046183,120320,%HOMEPATH%\Local Settings\Templ.exe"
- '%TEMP%\Console Window Host.exe'
- '%HOMEPATH%\Local Settings\Temps.exe'
- '%HOMEPATH%\Local Settings\Templ.exe'
- '%HOMEPATH%\Local Settings\Tempr.exe'