Техническая информация
- [<HKCU>\software\Microsoft\Windows\CurrentVersion\Run] '1619fabdd849bcee0f84bbc48a331f59' = '"%TEMP%\VPN\UPDATES\EnCryptedE.exe" ..'
- [<HKLM>\software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '1619fabdd849bcee0f84bbc48a331f59' = '"%TEMP%\VPN\UPDATES\EnCryptedE.exe" ..'
- %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\upnp device host\upnphost\udhisapi.dll
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\VPN\UPDATES\EnCryptedE.exe" "EnCryptedE.exe" ENABLE
- %TEMP%\nsy9993.tmp
- %TEMP%\vpn\updates\lower third.mp4
- %TEMP%\vpn\updates\encryptede.exe
- 'localhost':5553
- '23#.#55.255.250':1900
- ClassName: '\MSITPro::EventQueue' WindowName: ''
- ClassName: 'Type32_Main_Window' WindowName: ''
- ClassName: 'WMPlayerApp' WindowName: ''
- '%TEMP%\vpn\updates\encryptede.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\VPN\UPDATES\EnCryptedE.exe" "EnCryptedE.exe" ENABLE' (со скрытым окном)
- '%ProgramFiles(x86)%\windows media player\wmplayer.exe' /Play -Embedding