Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Logintech_000001' = '%WINDIR%\SysWOW64\rundll32.exe /sta {39980D1E-8C57-42CA-BFBA-2B1DBEDF00F0} "Keyboard"'
- %TEMP%\ixp000.tmp\add.txt
- %TEMP%\ixp000.tmp\amd.exe
- %TEMP%\ixp000.tmp\n1.ocx
- %TEMP%\ixp000.tmp\n2.ocx
- %TEMP%\ixp000.tmp\pc.txt
- %APPDATA%\nvidia\core.ocx
- %APPDATA%\nvidia\add.txt
- 'fk##xfc.com':1212
- 'fk##xfc.com':1212
- DNS ASK fk##xfc.com
- '%TEMP%\ixp000.tmp\amd.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cd %APPDATA%\Nvidia&&cmd /c timeout 1&&cmd /c reg.exe import add.txt' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c cd %APPDATA%\Nvidia&&cmd /c timeout 1&&cmd /c %WINDIR%\SysWOW64\rundll32.exe /sta {39980D1E-8C57-42CA-BFBA-2B1DBEDF00F0} 6:43:03 PM' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c cd %APPDATA%\Nvidia&&cmd /c timeout 1&&cmd /c reg.exe import add.txt
- '%WINDIR%\syswow64\cmd.exe' /c timeout 1
- '%WINDIR%\syswow64\timeout.exe' 1
- '%WINDIR%\syswow64\cmd.exe' /c reg.exe import add.txt
- '%WINDIR%\syswow64\cmd.exe' /c cd %APPDATA%\Nvidia&&cmd /c timeout 1&&cmd /c %WINDIR%\SysWOW64\rundll32.exe /sta {39980D1E-8C57-42CA-BFBA-2B1DBEDF00F0} 6:43:03 PM
- '%WINDIR%\syswow64\reg.exe' import add.txt
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\SysWOW64\rundll32.exe /sta {39980D1E-8C57-42CA-BFBA-2B1DBEDF00F0} 6:43:03 PM
- '%WINDIR%\syswow64\rundll32.exe' /sta {39980D1E-8C57-42CA-BFBA-2B1DBEDF00F0} 6:43:03 PM