Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\anydesk.exe.exe
- '%TEMP%\regedit.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -command Copy-Item '%TEMP%\RegEdit.exe' '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\anydesk.exe.exe'
- regedit.exe
- %TEMP%\regedit.exe
- '19#.#.101.153':80
- http://19#.#.101.153/013/nbv.exe
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding