Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '2f81b690c2fee4725ed473139432eaed' = '"%TEMP%\serie exercice.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '2f81b690c2fee4725ed473139432eaed' = '"%TEMP%\serie exercice.exe" ..'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\serie exercice.exe" "serie exercice.exe" ENABLE
- %ProgramFiles(x86)%\test\rufus-3.8.exe
- %ProgramFiles(x86)%\test\vicswors.vbs
- %TEMP%\rufb056.tmp
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- %LOCALAPPDATA%\tempwinlogon.exe
- %TEMP%\serie exercice.exe
- '9l###.ddns.net':44444
- DNS ASK 9l###.ddns.net
- ClassName: 'EDIT' WindowName: ''
- '%ProgramFiles(x86)%\test\rufus-3.8.exe'
- '%WINDIR%\syswow64\wscript.exe' "%ProgramFiles(x86)%\test\vicswors.vbs"
- '%LOCALAPPDATA%\tempwinlogon.exe'
- '%TEMP%\serie exercice.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\serie exercice.exe" "serie exercice.exe" ENABLE' (со скрытым окном)