Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Onedrive' = '%LOCALAPPDATA%\Microsoft\Windows\History\Onedrive\Onedrive.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %LOCALAPPDATA%\microsoft\windows\history\onedrive\onedrive.exe
- '11#.#4.205.132':1547
- 'ln####ram.p-e.kr':1547
- '15#.#20.115.201':1547
- '15#.#71.64.17':1547
- DNS ASK ln####ram.p-e.kr
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Remove-ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'Onedrive';New-ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'Onedrive' -V...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'