Техническая информация
- Системный антивирус (Защитник Windows)
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7750B51C-14D2-421E-8A78-6815F0870861}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] 'exe' = ''
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] 'exe' = ''
- <SYSTEM32>\grouppolicy\gpt.ini
- <SYSTEM32>\grouppolicy\machine\registry.pol
- %ALLUSERSPROFILE%\ntuser.pol
- %HOMEPATH%\pictures\minor policy\0r7sfukqg8njm7bd9aezmhu2.exe
- '94.##2.138.131':80
- 'ap#.#yip.com':443
- 'ip##fo.io':443
- 'vk.com':80
- 'vk.com':443
- http://94.##2.138.131/api/tracemap.php
- 'ap#.#yip.com':443
- 'ip##fo.io':443
- 'vk.com':80
- 'vk.com':443
- DNS ASK ap#.#yip.com
- DNS ASK ip##fo.io
- DNS ASK vk.com
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '<SYSTEM32>\raserver.exe' /offerraupdate