Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '3e936482e28cca4a48b713452330a269' = '"%TEMP%\Internet Explorer.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '3e936482e28cca4a48b713452330a269' = '"%TEMP%\Internet Explorer.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\3e936482e28cca4a48b713452330a269.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Internet Explorer.exe" "Internet Explorer.exe" ENABLE
- %TEMP%\internet explorer.exe
- DNS ASK go####00.ddns.net
- '%TEMP%\internet explorer.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Internet Explorer.exe" "Internet Explorer.exe" ENABLE' (со скрытым окном)