Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\s54d45s151f56a564sd561dd] 'ImagePath' = '%WINDIR%\ookyou.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\s54d45s151f56a564sd561dd] 'Start' = '00000002'
- '<SYSTEM32>\net.exe' stop 546
- '<SYSTEM32>\net.exe' stop 123
- '<SYSTEM32>\taskkill.exe' /f /im sysinfo2.exe
- '<SYSTEM32>\taskkill.exe' /f /im SVCH0ST.exe
- '<SYSTEM32>\taskkill.exe' /f /im sysinfo3.exe
- '<SYSTEM32>\net.exe' stop 9988
- '<SYSTEM32>\taskkill.exe' /f /im 1.exe
- '<SYSTEM32>\net.exe' stop AdobeFlashPlayerUpdatedo
- '<SYSTEM32>\net.exe' stop AdobeFlashPlayerUpdatedo3
- '<SYSTEM32>\net.exe' stop AdobeFlashPlayerUpdatedo2
- <SYSTEM32>\xmr86.exe
- %WINDIR%\ookyou.exe
- <SYSTEM32>\xmr86.exe
- 'lu###exp.com':5858
- 'lu###exp.com':8888
- DNS ASK lu###exp.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\xmr86.exe'
- '%WINDIR%\ookyou.exe'
- '<SYSTEM32>\net1.exe' stop 546
- '<SYSTEM32>\net1.exe' stop AdobeFlashPlayerUpdatedo3
- '<SYSTEM32>\net1.exe' stop 123
- '<SYSTEM32>\net1.exe' stop 9988
- '<SYSTEM32>\net1.exe' stop AdobeFlashPlayerUpdatedo
- '<SYSTEM32>\net1.exe' stop AdobeFlashPlayerUpdatedo2