Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ed98bbf13769247f752360fb362550e4' = '"%PROGRAMDATA%\CompPkgSrv.exe" ..'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'ed98bbf13769247f752360fb362550e4' = '"%PROGRAMDATA%\CompPkgSrv.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\ed98bbf13769247f752360fb362550e4.exe
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%PROGRAMDATA%\CompPkgSrv.exe" "CompPkgSrv.exe" ENABLE
- %PROGRAMDATA%\comppkgsrv.exe
- 'mi####tnet.kro.kr':5
- DNS ASK mi####tnet.kro.kr
- '%PROGRAMDATA%\comppkgsrv.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%PROGRAMDATA%\CompPkgSrv.exe" "CompPkgSrv.exe" ENABLE' (со скрытым окном)