Техническая информация
- [HKLM\Software\Classes\Y2G5HbzmiL\Shell\Open\Command] '' = '"%ALLUSERSPROFILE%\943158\ld5osW.exe" "%1"'
- <SYSTEM32>\tasks\mysystemboottask_uouslc
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoDrives' = '00020000'
- %TEMP%\dllf66e.tmp
- %WINDIR%\temp\fwtsqmfile02.sqm
- %TEMP%\dllf6c.tmp
- %ALLUSERSPROFILE%\943158\ld5osw.exe
- %ALLUSERSPROFILE%\943158\fvewiz.dll
- %ALLUSERSPROFILE%\943158\longlq.cl
- %LOCALAPPDATA%\ld5osw.exe
- %TEMP%\dllf6c.tmp
- %TEMP%\dllf66e.tmp
- '12#.#56.120.221':8081
- '12#.#56.120.221':8081
- DNS ASK lo###qcl.top
- 'localhost':56886
- 'localhost':51591
- 'localhost':61315
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- '%ALLUSERSPROFILE%\943158\ld5osw.exe'
- '<SYSTEM32>\schtasks.exe' /Create /TN "MySystemBootTask_UouslC" /TR "%ALLUSERSPROFILE%\943158\ld5osW.exe" /SC ONLOGON /RL HIGHEST /F (со скрытым окном)