Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '301c2f38399e4dce7de3b197eaa329d2' = '"%ALLUSERSPROFILE%\SQL .exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '301c2f38399e4dce7de3b197eaa329d2' = '"%ALLUSERSPROFILE%\SQL .exe" ..'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%ALLUSERSPROFILE%\SQL .exe" "SQL .exe" ENABLE
- %ALLUSERSPROFILE%\sql .exe
- %HOMEPATH%\desktop\~$fieldnotes1966.docx
- 'mo####r34.ddns.net':5566
- DNS ASK mo####r34.ddns.net
- ClassName: 'Progman' WindowName: ''
- '%ALLUSERSPROFILE%\sql .exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%ALLUSERSPROFILE%\SQL .exe" "SQL .exe" ENABLE' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%HOMEPATH%\Desktop\nwfieldnotes1966.docx"
- '%WINDIR%\explorer.exe'
- '%ProgramFiles(x86)%\google\chrome\application\chrome.exe'