Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, %LOCALAPPDATA%\DLZKBpxKL\amzn.exe'
- [<HKCU>\Software\Classes\ms-settings\shell\open\command] '' = 'powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -Command Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\DLZ...
- %LOCALAPPDATA%\dlzkbpxkl\amzn.exe
- '14#.#5.6.166':1337
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\ctfmon.exe'
- '%WINDIR%\syswow64\computerdefaults.exe'