Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows-Audio Driver' = '%ALLUSERSPROFILE%\wscntfy.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Windows-Network Component' = '%CommonProgramFiles%\lsmass.exe'
- [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{04cb9fa7-51ca-11ee-b2fe-806e6f6e6963}] 'StubPath' = '%ALLUSERSPROFILE%\wscntfy.exe -r'
- скрытых файлов
- Средство контроля пользовательских учетных записей (UAC)
- %ALLUSERSPROFILE%\wscntfy.exe
- %CommonProgramFiles%\lsmass.exe
- %ALLUSERSPROFILE%\wscntfy.exe
- %CommonProgramFiles%\lsmass.exe
- '<LOCALNET>.0.12':80
- DNS ASK ba##u.com
- '%ALLUSERSPROFILE%\wscntfy.exe'
- '%CommonProgramFiles%\lsmass.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "%ALLUSERSPROFILE%\wscntfy.exe"