Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\5691eb53dbf60e6cb2b1c6909232a062.exe
- '<LS_APPDATA>\tempwinlogon.exe'
- '%HOMEPATH%\windows defender.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%HOMEPATH%\windows defender.exe" "windows defender.exe" ENABLE
- %WINDIR%\explorer.exe
- <LS_APPDATA>\tempwinlogon.exe
- %HOMEPATH%\windows defender.exe
- DNS ASK do#####d-video.online
- DNS ASK kh#####gc.ddnsking.com
- DNS ASK bl##ger.com
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%HOMEPATH%\windows defender.exe" "windows defender.exe" ENABLE' (со скрытым окном)
- '%WINDIR%\explorer.exe'