Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'SPl8B' = '%LOCALAPPDATA%\InstallAgent\{yW65hzgzp45YQ}\SPl8B.exe'
- %LOCALAPPDATA%\installagent\{yw65hzgzp45yq}\spl8b.exe
- %LOCALAPPDATA%\installagent\{yw65hzgzp45yq}\spl8b.txt
- %LOCALAPPDATA%\installagent\{yw65hzgzp45yq}\ad_logic.dll
- %LOCALAPPDATA%\178bfbff000306f2
- %LOCALAPPDATA%\installagent\{yw65hzgzp45yq}\key
- '15#.#9.238.241':8080
- '15#.#9.238.241':12345
- http://15#.##.238.241:8080/9x.dll via 15#.#9.238.241
- '15#.#9.238.241':12345
- ClassName: '' WindowName: ''
- '%LOCALAPPDATA%\installagent\{yw65hzgzp45yq}\spl8b.exe'
- '<SYSTEM32>\cmd.exe' /c "%LOCALAPPDATA%\InstallAgent\{yW65hzgzp45YQ}\SPl8B.exe"' (со скрытым окном)
- '<Полный путь к файлу>' %LOCALAPPDATA%\InstallAgent\{yW65hzgzp45YQ} --{2kOTpIOB5kx04ocCCvBO} {2}' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%LOCALAPPDATA%\InstallAgent\{yW65hzgzp45YQ}\SPl8B.exe"