Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\aHRtdm5jL21yemd2dGyCAA==] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\aHRtdm5jL21yemd2dGyCAA==] 'ImagePath' = '%WINDIR%\ycogcg.exe'
- 'aHRtdm5jL21yemd2dGyCAA==' %WINDIR%\ycogcg.exe
- %WINDIR%\ycogcg.exe
- C:\2004.vbs
- C:\2004.vbs
- 'localhost':3455
- '%WINDIR%\ycogcg.exe'
- '%WINDIR%\syswow64\wscript.exe' "C:\2004.vbs"
- '%WINDIR%\ycogcg.exe' Win7
- '%WINDIR%\syswow64\wscript.exe' "C:\2004.vbs"' (со скрытым окном)