Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '6bcc34adf049d3b73859faaf47a22dbf' = '"%PROGRAMDATA%\System.exe" ..'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] '6bcc34adf049d3b73859faaf47a22dbf' = '"%PROGRAMDATA%\System.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\6bcc34adf049d3b73859faaf47a22dbf.exe
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%PROGRAMDATA%\System.exe" "System.exe" ENABLE
- %PROGRAMDATA%\system.exe
- 'tk###rt.kro.kr':50001
- DNS ASK tk###rt.kro.kr
- '%PROGRAMDATA%\system.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%PROGRAMDATA%\System.exe" "System.exe" ENABLE' (со скрытым окном)