Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'df257b89fc16ba9bc82269d9e445f1de' = '"%HOMEPATH%\ntoskrnl.exe" ..'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'df257b89fc16ba9bc82269d9e445f1de' = '"%HOMEPATH%\ntoskrnl.exe" ..'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%HOMEPATH%\ntoskrnl.exe" "ntoskrnl.exe" ENABLE
- %HOMEPATH%\ntoskrnl.exe
- 're###st.zz.am':1015
- '34.##9.100.209':443
- DNS ASK re###st.zz.am
- '%HOMEPATH%\ntoskrnl.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%HOMEPATH%\ntoskrnl.exe" "ntoskrnl.exe" ENABLE (со скрытым окном)