Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '57be547ea12520fdcf17d41041cfdb4e' = '"%APPDATA%\PasswordOnWakeSettingFlyout.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '57be547ea12520fdcf17d41041cfdb4e' = '"%APPDATA%\PasswordOnWakeSettingFlyout.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\57be547ea12520fdcf17d41041cfdb4e.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\PasswordOnWakeSettingFlyout.exe" "PasswordOnWakeSettingFlyout.exe" ENABLE
- passwordonwakesettingflyout.exe
- <Текущая директория>:{2f006c00-4c00-4b00-3900-650079005000}
- %APPDATA%\passwordonwakesettingflyout.exe
- %APPDATA%:{2f006c00-4c00-4b00-3900-650079005000}
- %ALLUSERSPROFILE%\isolated storage\{2f006c00-4c00-4b00-3900-650079005000}
- 'bo####16.ddns.net':1453
- DNS ASK bo####16.ddns.net
- '%APPDATA%\passwordonwakesettingflyout.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\PasswordOnWakeSettingFlyout.exe" "PasswordOnWakeSettingFlyout.exe" ENABLE' (со скрытым окном)