Техническая информация
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: 'RegmonClass', WindowName: ''
- %ALLUSERSPROFILE%\152119601237922022915161
- %ALLUSERSPROFILE%\ef202d2f98\rween.exe
- %ALLUSERSPROFILE%\729ee320c4413d\cred.dll
- %ALLUSERSPROFILE%\729ee320c4413d\scr.dll
- '18#.#15.113.207':80
- http://18#.#15.113.207/gb2pnjsjcs/plugins/cred.dll
- ClassName: 'File Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: 'Process Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%ALLUSERSPROFILE%\ef202d2f98\rween.exe'
- '%ALLUSERSPROFILE%\ef202d2f98\rween.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /f /v Startup /t REG_SZ /d %ALLUSERSPROFILE%\ef202d2f98\' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /f /v Startup /t REG_SZ /d %ALLUSERSPROFILE%\ef202d2f98\
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /f /v Startup /t REG_SZ /d %ALLUSERSPROFILE%\ef202d2f98\