Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\bit5ce9.tmp
- %WINDIR%\syswow64\mstsc.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\1d8c5a37.png
- %APPDATA%\icq-profile\update\bit5362.tmp
- %TEMP%\322cd1c2.lnk
- %APPDATA%\icq-profile\update\bit5362.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bit5ce9.tmp
- %APPDATA%\icq-profile\update\bit5362.tmp в %APPDATA%\icq-profile\update\rgsvr30.exe
- 'i.##gur.com':443
- DNS ASK i.##gur.com
- '<SYSTEM32>\cmd.exe' /c "reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /v "%APPDATA%\ICQ-Profile\Update" /t REG_DWORD /d 0"' (со скрытым окном)
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\cmd.exe'
- '<SYSTEM32>\cmd.exe' /c "reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /v "%APPDATA%\ICQ-Profile\Update" /t REG_DWORD /d 0"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /v "%APPDATA%\ICQ-Profile\Update" /t REG_DWORD /d 0