Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'smsr' = '<Полный путь к файлу>'
- [<HKLM>\System\CurrentControlSet\Services\AeroadminService] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\AeroadminService] 'ImagePath' = '"%TEMP%\svhost.exe" s -sid 1 '
- 'AeroadminService' "%TEMP%\svhost.exe" s -sid 1
- [<HKCU>\Software\Microsoft\Internet Account Manager]
- [<HKLM>\Software\Microsoft\Windows Mail]
- [<HKCU>\Software\Microsoft\Windows Mail]
- %TEMP%\aut68ff.tmp
- %TEMP%\svhost.exe
- %ALLUSERSPROFILE%\aeroadmin\config
- %ALLUSERSPROFILE%\aeroadmin\log.txt
- %ALLUSERSPROFILE%\aeroadmin\guid.bin
- %ALLUSERSPROFILE%\aeroadmin\settings.bin
- %TEMP%\captured.jpg
- %TEMP%\svhost.exe
- %TEMP%\aut68ff.tmp
- 'au####.aeroadmin.com':443
- 'ma##.#mtp2go.com':443
- 'microsoft.com':80
- 'au####.aeroadmin.com':443
- 'ma##.#mtp2go.com':443
- DNS ASK au####.aeroadmin.com
- DNS ASK ma##.#mtp2go.com
- DNS ASK microsoft.com
- ClassName: 'CustomWndCls' WindowName: 'CustomWndCls'
- '%TEMP%\svhost.exe'
- '%TEMP%\svhost.exe' s -sid 1
- '%TEMP%\svhost.exe' a -sid 1