Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '780b5df8fda898f39851917d8a235940' = '"%TEMP%\Svchost.exe" ..'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '780b5df8fda898f39851917d8a235940' = '"%TEMP%\Svchost.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\780b5df8fda898f39851917d8a235940.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Svchost.exe" "Svchost.exe" ENABLE
- %TEMP%\server.exe
- %TEMP%\program.exe
- %TEMP%\svchost.exe
- DNS ASK ki####2.ddns.net
- '%TEMP%\server.exe'
- '%TEMP%\program.exe'
- '%TEMP%\svchost.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle hidden (Start-Process -FilePath $env:Temp\Server.exe)' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle hidden (Start-Process -FilePath $env:Temp\Program.exe)' (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Svchost.exe" "Svchost.exe" ENABLE' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle hidden (Start-Process -FilePath $env:Temp\Server.exe)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\dw20.exe' -x -s 876
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle hidden (Start-Process -FilePath $env:Temp\Program.exe)