Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'fad4b7384a3d59b5a0936ba3f1fa9b72' = '"%TEMP%\Windows Security.exe" ..'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'fad4b7384a3d59b5a0936ba3f1fa9b72' = '"%TEMP%\Windows Security.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\fad4b7384a3d59b5a0936ba3f1fa9b72.exe
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\Windows Security.exe" "Windows Security.exe" ENABLE
- %TEMP%\windows security.exe
- 'pa######rivers.gl.at.ply.gg':15267
- DNS ASK pa######rivers.gl.at.ply.gg
- '%TEMP%\windows security.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\Windows Security.exe" "Windows Security.exe" ENABLE (со скрытым окном)