Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'LuminosityLink' = '"%ALLUSERSPROFILE%\471257\Luminosity.exe" -a /a'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'LuminosityLink' = '"%ALLUSERSPROFILE%\471257\Luminosity.exe" -a /a'
- %APPDATA%\microsoft\windows\start menu\programs\startup\filename.bat
- svchost.exe
- %APPDATA%\subfolder\filename.exe
- %TEMP%\svchost.exe
- %ALLUSERSPROFILE%\dea11b3218b246777b267bdce2ee955d56edde5d
- %ALLUSERSPROFILE%\471257\luminosity.exe
- %ALLUSERSPROFILE%\dea11b3218b246777b267bdce2ee955d56edde5d
- DNS ASK kr###x.ddns.net
- '%TEMP%\svchost.exe'