Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'QQ°²È«ÖÐÐÄ' = 'C:\Users\Public\1.exe'
- [HKLM\System\CurrentControlSet\Services\CreateSvcRpc_804185] 'ImagePath' = 'reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v QQ°²È«ÖÐÐÄ /t REG_SZ /d "C:\Users\Public\1.exe" /f'
- 'CreateSvcRpc_804185' reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v QQ°²È«ÖÐÐÄ /t REG_SZ /d "C:\Users\Public\1.exe" /f
- <SYSTEM32>\reg.exe
- C:\users\public\proj.exe
- C:\users\public\1.exe
- '38.#.187.62':80
- '47.##1.11.103':80
- '47.##1.11.103':1010
- http://38.#.187.62/dsaf47.111.11.103.txt
- http://47.##1.11.103/mm.txt
- http://47.##1.11.103/m.txt
- 'C:\users\public\proj.exe'
- 'C:\users\public\1.exe'
- '%WINDIR%\syswow64\wbem\wmic.exe' process get ExecutablePath,Name' (со скрытым окном)
- 'C:\users\public\1.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\wbem\wmic.exe' process get ExecutablePath,Name
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v QQ°²È«ÖÐÐÄ /t REG_SZ /d "C:\Users\Public\1.exe" /f