Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Audio' = 'cmd.exe /c START /MIN Powershell.exe -ExecutionPolicy ByPass -windowstyle hidden -noexit -File "%PROGRAMDATA%\CEymdyPFJIpyOyz.p...
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "<SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe" "powershell.exe" ENABLE
- %PROGRAMDATA%\ceymdypfjipyoyz.ps1
- %TEMP%\csa\61311b1a8af4e84f1992588ba5e0b89c\61311b1a8af4e84f1992588ba5e0b89c.bat
- 'localhost':3456
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -executionpolicy bypass %PROGRAMDATA%\CEymdyPFJIpyOyz.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -executionpolicy bypass %PROGRAMDATA%\CEymdyPFJIpyOyz.ps1' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\CSA\61311b1a8af4e84f1992588ba5e0b89c\61311b1a8af4e84f1992588ba5e0b89c.bat' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\CSA\61311b1a8af4e84f1992588ba5e0b89c\61311b1a8af4e84f1992588ba5e0b89c.bat