Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '9rXPHF' = '%LOCALAPPDATA%\InstallAgent\{C8B5tMz48a2}\9rXPHF.exe'
- %LOCALAPPDATA%\installagent\{c8b5tmz48a2}\9rxphf.exe
- %LOCALAPPDATA%\installagent\{c8b5tmz48a2}\9rxphf.txt
- %LOCALAPPDATA%\installagent\{c8b5tmz48a2}\ad_logic.dll
- %LOCALAPPDATA%\178bfbff00050657
- %LOCALAPPDATA%\installagent\{c8b5tmz48a2}\key
- 'sl##888.com':8080
- 'sl##888.com':12345
- http://sl####8.com:8080/9x.dll via sl##888.com
- 'sl##888.com':12345
- DNS ASK sl##888.com
- ClassName: '' WindowName: ''
- '%LOCALAPPDATA%\installagent\{c8b5tmz48a2}\9rxphf.exe'
- '<SYSTEM32>\cmd.exe' /c "%LOCALAPPDATA%\InstallAgent\{C8B5tMz48a2}\9rXPHF.exe"' (со скрытым окном)
- '<Полный путь к файлу>' %LOCALAPPDATA%\InstallAgent\{C8B5tMz48a2} --{1xgq30vy6XYtWFb} {2}' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%LOCALAPPDATA%\InstallAgent\{C8B5tMz48a2}\9rXPHF.exe"