Техническая информация
- Системный антивирус (Защитник Windows)
- setup.exe
- %TEMP%\rarsfx0\darkspyloader.exe
- %TEMP%\rarsfx0\megasyncsetup64.exe
- %TEMP%\rarsfx0\setup.exe
- %TEMP%\aut6b7e.tmp
- %TEMP%\umusixm
- %WINDIR%\temp\aut79a1.tmp
- %WINDIR%\temp\xtjwofe
- %TEMP%\aut6b7e.tmp
- %TEMP%\umusixm
- %WINDIR%\temp\aut79a1.tmp
- %WINDIR%\temp\xtjwofe
- %ALLUSERSPROFILE%\ntuser.pol
- %HOMEPATH%\ntuser.pol
- %ALLUSERSPROFILE%\tempntuser.pol
- 'ga###abpro.club':80
- http://ga###abpro.club/
- DNS ASK ga###abpro.club
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\darkspyloader.exe' /D
- '%TEMP%\rarsfx0\darkspyloader.exe' /SYS 1
- '%TEMP%\rarsfx0\setup.exe'
- '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '<SYSTEM32>\raserver.exe' /offerraupdate