Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AutoStart' = 'rundll32.exe %ALLUSERSPROFILE%\Exchange.dll,Start'
- '<SYSTEM32>\cmd.exe' /c start /b %ALLUSERSPROFILE%\tt.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Start-Process rundll32.exe %ALLUSERSPROFILE%\Exchange.dll,Start
- %ALLUSERSPROFILE%\exchange.dll
- %ALLUSERSPROFILE%\tt.bat
- %ALLUSERSPROFILE%\t.txt
- DNS ASK 00####################9167641343BC7A1D0000000000000E1h_ge94zP.googlechromeupdate.ga
- '<SYSTEM32>\cmd.exe' /K %ALLUSERSPROFILE%\tt.bat
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v AutoStart /t REG_SZ /d "rundll32.exe %ALLUSERSPROFILE%\Exchange.dll,Start"
- '<SYSTEM32>\rundll32.exe' %ALLUSERSPROFILE%\Exchange.dll Start