Техническая информация
- [HKLM\System\CurrentControlSet\Services\Rswoeo igyeekii] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rswoeo igyeekii] 'ImagePath' = '%WINDIR%\Kiwwqe.pif -auto'
- 'Rswoeo igyeekii' %WINDIR%\Kiwwqe.pif -auto
- %TEMP%\e3f31.tmp
- %TEMP%\e3f70.tmp
- %TEMP%\e3f81.tmp
- %TEMP%\yq.exe
- C:\input.txt
- %WINDIR%\kiwwqe.pif
- %TEMP%\e3f31.tmp
- %TEMP%\e3f70.tmp
- %TEMP%\e3f81.tmp
- C:\input.txt
- %TEMP%\yq.exe
- C:\input.txt
- '22#.#87.222.105':2222
- 'na###uan.com':2021
- '22#.#87.222.105':2222
- DNS ASK 1.###j999.xyz
- DNS ASK na###uan.com
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- '%TEMP%\yq.exe'
- '%WINDIR%\kiwwqe.pif' -auto
- '%WINDIR%\kiwwqe.pif' -acsi
- '%TEMP%\yq.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c del %TEMP%\yq.exe > nul' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c del %TEMP%\yq.exe > nul