Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mkv' = '%APPDATA%\system\film.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '6819f12b2546b2394b37a88fa058572d' = '"%TEMP%\Dxhx.exe" ..'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '6819f12b2546b2394b37a88fa058572d' = '"%TEMP%\Dxhx.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\6819f12b2546b2394b37a88fa058572d.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Dxhx.exe" "Dxhx.exe" ENABLE
- %APPDATA%\system\film.exe
- %TEMP%\dxhx.exe
- DNS ASK ja#####orn512.noip.me
- '%TEMP%\dxhx.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Dxhx.exe" "Dxhx.exe" ENABLE (со скрытым окном)