Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\swsnikmmvk.url
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %WINDIR%\WinRing0x64.sys
- %WINDIR%\microsoft.net\framework\v4.0.30319\mscorsvw.exe
- iexplore.exe
- %HOMEPATH%\desktop\setupclient.exe
- %ALLUSERSPROFILE%\rxthfcrhyt\cfgi
- %ALLUSERSPROFILE%\rxthfcrhyt\cfg
- %ALLUSERSPROFILE%\rxthfcrhyt\setupclient
- %ALLUSERSPROFILE%\rxthfcrhyt\r.vbs
- %ALLUSERSPROFILE%\rxthfcrhyt\r.vbs
- %ALLUSERSPROFILE%\rxthfcrhyt\setupclient в %ALLUSERSPROFILE%\rxthfcrhyt\setupclient.exe
- %ALLUSERSPROFILE%\rxthfcrhyt\r.vbs
- 'sg.##nexmr.com':80
- DNS ASK sg.##nexmr.com
- '%HOMEPATH%\desktop\setupclient.exe'
- '%WINDIR%\syswow64\cmd.exe' /c, "%HOMEPATH%\Desktop\SetupClient.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c, "%HOMEPATH%\Desktop\SetupClient.exe"
- '%WINDIR%\notepad.exe' -c "%ALLUSERSPROFILE%\RXTHfCrhyT\cfg"
- '%WINDIR%\syswow64\cmd.exe' /C WScript "%ALLUSERSPROFILE%\RXTHfCrhyT\r.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%ALLUSERSPROFILE%\RXTHfCrhyT\r.vbs"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\mscorsvw.exe'
- '%WINDIR%\notepad.exe' -c "%ALLUSERSPROFILE%\RXTHfCrhyT\cfgi"