Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'IE Crash Handler' = '%APPDATA%\IE Crash Handler\CrashHandler.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %TEMP%\dwass.txt
- %TEMP%\xuowokkybzlzf.exe
- %APPDATA%\ie crash handler\crashhandler.exe
- 'si########k1234-46140.portmap.host':46140
- DNS ASK si########k1234-46140.portmap.host
- '%TEMP%\xuowokkybzlzf.exe'
- '%WINDIR%\syswow64\notepad.exe' %TEMP%\Dwass.txt
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Remove-ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'IE Crash Handler';New-ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'IE C...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'