Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\419012e80ea251f13665b1ce34243a2b.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ALLUSERSPROFILE%\taskhost.exe' = '%ALLUSERSPROFILE%\taskhost.exe:*:En...
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%ALLUSERSPROFILE%\taskhost.exe" "taskhost.exe" ENABLE
- %ALLUSERSPROFILE%\taskhost.exe
- 'sp##.ze.am':5553
- DNS ASK sp##.ze.am
- '%ALLUSERSPROFILE%\taskhost.exe'