Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'FrontLine Protection GUI Application' = '<SYSTEM32>\protect.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{DE2351DE-13DF-3741-053A-6EF8A370E94C}] 'StubPath' = '<SYSTEM32>\protect.exe'
- %WINDIR%\Explorer.EXE
- iexplore.exe
- ClassName: 'RegMonClass' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- <SYSTEM32>\protect.exe
- %TEMP%\0CB23DB6.TMP
- '21#.#26.192.12':3389
- '21#.#0.75.36':3389
- '95.#.44.110':3389
- '82.##7.178.7':3389
- '84.##.15.110':3389
- '83.##.172.135':3389