Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'MsRas' = '%APPDATA%\RasMS\RasMS.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'MsRas' = '%APPDATA%\RasMS\RasMS.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'MsRas' = '%APPDATA%\RasMS\RasMS.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'MsRas' = '%APPDATA%\RasMS\RasMS.exe'
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\svchost.exe
- %APPDATA%\hhe4gzyj.cfg
- %APPDATA%\rasms\rasms.exe
- %APPDATA%\hhe4gzyj.xtr
- %APPDATA%\hhe4gzyj.cfg
- %APPDATA%\rasms\rasms.exe
- %APPDATA%\hhe4gzyj.xtr
- '%APPDATA%\rasms\rasms.exe'
- '%APPDATA%\rasms\rasms.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\svchost.exe'