Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'fachbab' = '"%ALLUSERSPROFILE%\fbcafdk\Autoit3.exe" %ALLUSERSPROFILE%\fbcafdk\decgeaf.a3x'
- C:\temp\test\autoit3.exe
- C:\temp\test\script.a3x
- %APPDATA%\bcfkgcf
- C:\temp\fgfaehd
- %ALLUSERSPROFILE%\fbcafdk\decgeaf.a3x
- %ALLUSERSPROFILE%\fbcafdk\autoit3.exe
- %ALLUSERSPROFILE%\fbcafdk\fdkefee
- C:\temp\fgfaehd
- '66.##.96.199':80
- '66.##.96.199':80
- 'C:\temp\test\autoit3.exe' c:\temp\test\script.a3x
- '%WINDIR%\syswow64\cmd.exe' /c wmic ComputerSystem get domain > %ALLUSERSPROFILE%\fbcafdk\fdkefee
- '%WINDIR%\syswow64\wbem\wmic.exe' ComputerSystem get domain