Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'fe3d331c23f1f8eee8da955c55efe15d' = '"%TEMP%\57yhyh.ExE" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'fe3d331c23f1f8eee8da955c55efe15d' = '"%TEMP%\57yhyh.ExE" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\fe3d331c23f1f8eee8da955c55efe15d.exe
- '%TEMP%\57yhyh.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\57yhyh.ExE" "57yhyh.ExE" ENABLE
- %TEMP%\57yhyh.exe
- '85.##5.234.185':7575
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\57yhyh.ExE" "57yhyh.ExE" ENABLE' (со скрытым окном)