Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Scrkey' = '"C:\Users\Public\Documents\KeyScr\KeyScr.exe" -HIDE'
- C:\users\public\documents\keyscr\keyscr.exe
- C:\users\public\documents\keyscr\keylog.dll
- C:\users\public\documents\keyscr\ttscr.ini
- %TEMP%\temp.txt
- C:\users\public\documents\screen\2022-04-18 22-36-34.db
- C:\users\public\documents\screen\2022-04-18 22-37-04.db
- 'ad.##aohn.com':80
- http://ad.##aohn.com/keyscr/main9.html
- DNS ASK ad.##aohn.com
- ClassName: '' WindowName: 'ÖÐÎļüÅ̼ǼÆ÷v2.1'
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- 'C:\users\public\documents\keyscr\keyscr.exe'
- '%WINDIR%\syswow64\notepad.exe' %TEMP%\temp.txt