Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rundll32' = '%WINDIR%\rundll32.exe'
- %APPDATA%\WUDFdrv.exe
- %WINDIR%\rundll32.exe
- 'ma#.#aver.com':443
- DNS ASK ma#.#aver.com
- '<SYSTEM32>\cmd.exe' /C "netsh advfirewall firewall show rule name=\"rundll32\""
- '<SYSTEM32>\netsh.exe' advfirewall firewall show rule name=\"rundll32\"
- '<SYSTEM32>\cmd.exe' /Q /C reg add HKCU\Software\AppDatas /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\AppDatas /f