Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run\] 'Dv8161-E2WPIJ' = '"%ALLUSERSPROFILE%\Davinci\8161.exe"'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'Dv8161-E2WPIJ' = '"%ALLUSERSPROFILE%\Davinci\8161.exe"'
- '%WINDIR%\explorer.exe' "\\89.23.98.22\LN\"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Stop-Process -Name explorer
- 8161.exe
- %WINDIR%\explorer.exe
- unc\89.23.98.22\pipe\srvsvc
- %ALLUSERSPROFILE%\davinci\8161.exe
- '89.#3.98.22':445
- '95.##4.26.199':80
- '95.##4.26.199':465
- '95.##4.26.199':21
- '95.##4.26.199':8080
- '95.##4.26.190':80
- '89.#3.98.22':445
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '%ALLUSERSPROFILE%\davinci\8161.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Stop-Process -Name explorer' (со скрытым окном)
- '%WINDIR%\explorer.exe'