Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '??????' = 'C:\Users\Public\Downloads\Tencente\d23f782f963f91a7\beeba6a16bde130f9c91ede0469467dd.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1201' = '00000000'
- C:\users\public\downloads\tencente\1.7z
- C:\users\public\downloads\tencente\d23f782f963f91a7\xbox.png
- C:\users\public\downloads\tencente\d23f782f963f91a7\qbcore.dll
- C:\users\public\documents\43f9c59cedbefa31.quanshy1
- %APPDATA%\air2\5aaa15985431eded.lnk
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012021061020210611\index.dat
- C:\users\public\downloads\tencente\d23f782f963f91a7\xbox.png в C:\users\public\downloads\tencente\d23f782f963f91a7\beeba6a16bde130f9c91ede0469467dd.exe
- '20#.#.121.239':1234
- '20#.#.121.239':1234
- ClassName: '' WindowName: ''
- ClassName: 'DirectUIHWND' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- 'C:\users\public\downloads\tencente\d23f782f963f91a7\beeba6a16bde130f9c91ede0469467dd.exe'
- '%ProgramFiles%\internet explorer\iexplore.exe' file:///C:/Users/Public/Documents/43f9c59cedbefa31.quanshy1