Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '*Mouhn' = 'rundll32.exe %APPDATA%\Lopeunt.dll,EntryPoint'
- %WINDIR%\syswow64\regsvr32.exe
- %APPDATA%\lopeunt.dll
- '19#.#42.146.21':2404
- 'ge###ugin.net':80
- http://ge###ugin.net/json.gp
- '19#.#42.146.21':2404
- DNS ASK ge###ugin.net
- '%WINDIR%\syswow64\regsvr32.exe'
- '%WINDIR%\syswow64\cmd.exe' /C reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "*Mouhn" /t REG_SZ /d "rundll32.exe %APPDATA%\Lopeunt.dll",EntryPoint /f & exit
- '%WINDIR%\syswow64\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "*Mouhn" /t REG_SZ /d "rundll32.exe %APPDATA%\Lopeunt.dll",EntryPoint /f