Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'ProcessMemoryDiagnosticEvents' = 'wscript.exe "%HOMEPATH%\Favorites\jacket.adf" //e:vbscript //b /adf /kdc /ato /nef '
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'RunFullMemoryDiagnostic' = 'wscript.exe "%HOMEPATH%\Favorites\jolly.kdc" //e:vbscript //b /adf /kdc /ato /nef '
- <SYSTEM32>\tasks\processmemorydiagnosticevents
- <SYSTEM32>\tasks\runfullmemorydiagnostic
- %HOMEPATH%\trash.dll
- %HOMEPATH%\favorites\jacket.adf
- %HOMEPATH%\favorites\jolly.kdc
- %TEMP%\arrestw1v
- %HOMEPATH%\trash.dll
- DNS ASK Ev####.squeamish.ru
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\Favorites\jacket.adf" //e:vbscript //b /adf /kdc /ato /nef
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\Favorites\jolly.kdc" //e:vbscript //b /adf /kdc /ato /nef
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\Favorites\jacket.adf" //e:vbscript //b /adf /kdc /ato /nef' (со скрытым окном)
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\Favorites\jolly.kdc" //e:vbscript //b /adf /kdc /ato /nef' (со скрытым окном)