Техническая информация
- [HKLM\Software\Classes\Counsellor\Shell\Open\Command] '' = 'wscript.exe //E:vbscript "%1"'
- %TEMP%\thomasinaupdate.exe
- %TEMP%\tmp9e8f.tmp.bat
- nul
- %WINDIR%\temp\flourishing.ion
- %APPDATA%\microsoft\windows\start menu\programs\flourishing.ion
- 'ap####.##englongfangchan.com':1433
- 'ap####.##englongfangchan.com':1434
- DNS ASK ap####.##englongfangchan.com
- '%TEMP%\thomasinaupdate.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp9E8F.tmp.bat" "' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp9E8F.tmp.bat" "
- '<SYSTEM32>\timeout.exe' 3
- '<SYSTEM32>\subst.exe' I: "%APPDATA%\Microsoft\Windows\Start Menu\Programs"