Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'coaster' = '%WINDIR%\svchost.exe'
- %WINDIR%\syswow64\plugin.exe
- %WINDIR%\svchost.exe
- %WINDIR%\syswow64\plugin.exe в %WINDIR%\syswow64\917129.bak
- 'xj######.e2.luyouxia.net':32439
- '17#.#4.207.39':8001
- 'xj######.e2.luyouxia.net':32439
- DNS ASK xj######.e2.luyouxia.net
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- '%WINDIR%\syswow64\plugin.exe'
- '%WINDIR%\syswow64\plugin.exe' ' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<Полный путь к файлу>"