Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WUDSHost' = '"%LOCALAPPDATA%\Plugin.sk_apiZ\WUDSHost.exe"'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="SK_API1" dir=in action=allow program="%LOCALAPPDATA%\Plugin.sk_apiZ\WUDSHost.exe" enable=yes
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="SK_API2" dir=out action=allow program="%LOCALAPPDATA%\Plugin.sk_apiZ\WUDSHost.exe" enable=yes
- [<HKCU>\Software\Microsoft\Windows Mail]
- %TEMP%\aut3db2.tmp
- %LOCALAPPDATA%\plugin.sk_apiz\wudshost.exe
- %LOCALAPPDATA%\plugin.sk_apiz\src_9de45.bin
- %TEMP%\aut3db2.tmp
- 'sm##.gmail.com':465
- DNS ASK sm##.gmail.com
- '%LOCALAPPDATA%\plugin.sk_apiz\wudshost.exe'
- '%WINDIR%\syswow64\cmd.exe' /C netsh wlan show profiles' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall firewall add rule name="SK_API1" dir=in action=allow program="%LOCALAPPDATA%\Plugin.sk_apiZ\WUDSHost.exe" enable=yes
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall firewall add rule name="SK_API2" dir=out action=allow program="%LOCALAPPDATA%\Plugin.sk_apiZ\WUDSHost.exe" enable=yes
- '%WINDIR%\syswow64\cmd.exe' /C netsh wlan show profiles
- '%WINDIR%\syswow64\netsh.exe' wlan show profiles