Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'KhKOjdxRMO' = 'C:\Users\Public\KhKOjdxRMO.vbs'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %APPDATA%\securityhealthsystray\aadauthhelper.bat
- C:\users\public\khkojdxrmo.vbs
- '93.##7.75.154':3500
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'