Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '23rf' = '<SYSTEM32>\CebEx\cb9x.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'CebEx' = '<SYSTEM32>\CebEx\cb9x.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'CbEx' = '<SYSTEM32>\CebEx\cb9x.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'CbEx' = '<SYSTEM32>\CebEx\cb9x.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{I52KN27B-P14M-XWK0-N55K-8M5M42X3HMW1}] 'StubPath' = '<SYSTEM32>\CebEx\cb9x.exe Restart'
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\988323.exe
- %WINDIR%\syswow64\cebex\cb9x.exe
- %WINDIR%\syswow64\cebex\cb9x.exe
- %TEMP%\988323.exe
- ClassName: 'shell_traywnd' WindowName: ''
- '%TEMP%\988323.exe'
- '%TEMP%\988323.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\explorer.exe'