Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'b112e20fe12960d6d6ec49a46df7f487' = '"%TEMP%\ظ…ظ†ط¸ظˆظ…ط© ظ„ظٹط¨ظٹط§ظ†ط§ ظˆط§ظ„ظ…ط¯ط§ط± 2014 .exe" ..'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'b112e20fe12960d6d6ec49a46df7f487' = '"%TEMP%\ظ…ظ†ط¸ظˆظ…ط© ظ„ظٹط¨ظٹط§ظ†ط§ ظˆط§ظ„ظ…ط¯ط§ط± 2014 .exe" ..'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\ظ…ظ†طВёظˆظ…طВ© ظ„ظٹطВЁظٹطВ§ظ†طВ§ ظˆطВ§ظ„ظ…طВЇطВ§طВ± 2014 .ex...
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\ظ…ظ†طВёظˆظ…طВ© ظ„ظٹطВЁظٹطВ§ظ†طВ§ ظˆطВ§ظ„ظ…طВЇطВ§طВ± 2014 .exe" "ظ…ظ†طВёظˆظ…طВ© ظ„ظٹطВЁظٹطВ§ظ†طВ§ ظˆطВ§ظ„ظ…طВЇطВ§طВ± 2014 .exe" ENABLE
- %TEMP%\ظ…ظ†طВёظˆظ…طВ© ظ„ظٹطВЁظٹطВ§ظ†طВ§ ظˆطВ§ظ„ظ…طВЇطВ§طВ± 2014 .exe
- DNS ASK yo####ost.no-ip.biz
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\ظ…ظ†طВёظˆظ…طВ© ظ„ظٹطВЁظٹطВ§ظ†طВ§ ظˆطВ§ظ„ظ…طВЇطВ§طВ± 2014 .exe" "ظ…ظ†طВёظˆظ…طВ© ظ„ظٹطВЁظٹطВ§ظ†طВ§ ظˆطВ§ظ„ظ…طВЇطВ§طВ± 2014 .exe" ENABLE' (со скрытым окном)