Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\scvhost.exe' = '<SYSTEM32>\scvhost.exe:*:Enabled:dns'
- '<SYSTEM32>\scvhost.exe' <SYSTEM32>\miyaka.ini
- '<SYSTEM32>\ping.exe' www.google.com -n 4
- '<SYSTEM32>\wscript.exe' "%WINDIR%\msagent\chars\miyaka.vbs"
- '%WINDIR%\msagent\agentsvr.exe' -Embedding
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram <SYSTEM32>\scvhost.exe dns enable
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\msagent\chars\0.bat" "
- '<SYSTEM32>\attrib.exe' <SYSTEM32>\scvhost.exe +h +s
- '<SYSTEM32>\attrib.exe' <SYSTEM32>\miyaka.exe +h +s
- <SYSTEM32>\scvhost.exe
- %WINDIR%\msagent\chars\Reaper.acs
- C:\go
- <SYSTEM32>\miyaka.ini
- %WINDIR%\msagent\chars\miyaka.vbs
- %WINDIR%\msagent\chars\delme.bat
- %WINDIR%\msagent\chars\0.bat
- %WINDIR%\msagent\chars\miyaka.ini
- %WINDIR%\msagent\chars\miyaka.dll
- <SYSTEM32>\scvhost.exe
- 'tr###micro.com':80
- tr###micro.com/cgi/cfg.bin
- tr###micro.com/up.cgi
- DNS ASK www.google.com
- DNS ASK tr###micro.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'