Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AutoStart' = 'rundll32.exe %ALLUSERSPROFILE%\Exchange.dll,Start'
- '<SYSTEM32>\cmd.exe' /c start /b %ALLUSERSPROFILE%\tt.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Start-Process rundll32.exe %ALLUSERSPROFILE%\Exchange.dll,Start
- %ALLUSERSPROFILE%\exchange.dll
- %ALLUSERSPROFILE%\tt.bat
- %ALLUSERSPROFILE%\t.txt
- DNS ASK 00####################CF158147187AAADB0000000000000yz7_owf2AP.googlechromeupdate.ml
- '<SYSTEM32>\cmd.exe' /K %ALLUSERSPROFILE%\tt.bat
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v AutoStart /t REG_SZ /d "rundll32.exe %ALLUSERSPROFILE%\Exchange.dll,Start"
- '<SYSTEM32>\rundll32.exe' %ALLUSERSPROFILE%\Exchange.dll Start