Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'setuptemp.exe' = '"%HOMEPATH%\My Documentstempletsetup.exe" ..'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%HOMEPATH%\My Documentstempletsetup.exe' = '%HOMEPATH%\My Document...
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%HOMEPATH%\My Documentstempletsetup.exe" "My Documentstempletsetup.exe" ENABLE
- %HOMEPATH%\my documentseveryonepiano_setup.exe
- %HOMEPATH%\my documentstempletsetup.exe
- %TEMP%\is-keu12.tmp\my documentseveryonepiano_setup.tmp
- %TEMP%\setuptemp.exe
- http://pa###bin.com/raw.php?i=########
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
- DNS ASK pa###bin.com
- '%HOMEPATH%\my documentseveryonepiano_setup.exe'
- '%HOMEPATH%\my documentstempletsetup.exe'
- '%TEMP%\is-keu12.tmp\my documentseveryonepiano_setup.tmp' /SL5="$10214,4420426,66048,%HOMEPATH%\My DocumentsEveryonePiano_Setup.exe"
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%HOMEPATH%\My Documentstempletsetup.exe" "My Documentstempletsetup.exe" ENABLE' (со скрытым окном)