Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'devwin' = 'devwin.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run] 'devwin' = 'devwin.exe'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 'c:\0jpz.exe' = 'c:\0jpz.exe:*:Enabled:devwin'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram 1.exe 1 ENABLE
- ClassName: '_Oscar_StatusNotify', WindowName: ''
- ClassName: 'MSNHiddenWindowClass', WindowName: ''
- C:\0jpz.exe
- %WINDIR%\devwin.exe
- %WINDIR%\devwin.exe
- DNS ASK ir#.#ytuxx.com
- ClassName: '' WindowName: 'abc'
- ClassName: '__oxFrame.class__' WindowName: ''
- ClassName: 'TskMultiChatForm.UnicodeClass' WindowName: ''
- ClassName: 'Message Session' WindowName: ''
- 'C:\0jpz.exe'
- '%WINDIR%\devwin.exe'
- 'C:\0jpz.exe' ' (со скрытым окном)
- '%WINDIR%\devwin.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram 1.exe 1 ENABLE' (со скрытым окном)