Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'igfxmsw' = 'C:\intel\logs\audiodq.exe'
- %WINDIR%\syswow64\cmd.exe
- C:\intel\logs\cetc technology transfer.docx
- C:\intel\logs\audiodq.exe
- C:\intel\logs\~$tc technology transfer.docx
- DNS ASK ar#####heworld123.net
- ClassName: 'EDIT' WindowName: ''
- 'C:\intel\logs\audiodq.exe'
- '%WINDIR%\syswow64\cmd.exe' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "C:\intel\logs\CETC Technology Transfer.docx"
- '%WINDIR%\syswow64\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v igfxmsw /t REG_SZ /d "C:\intel\logs\audiodq.exe"