Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Explorer.exe' = '"%LOCALAPPDATA%\Explorer.exe"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\explorer.exe
- %WINDIR%\temp\explorer.exe
- %LOCALAPPDATA%\start.exe
- %LOCALAPPDATA%\explorer.exe
- 'pa###bin.com':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'pa###bin.com':443
- DNS ASK pa###bin.com
- DNS ASK pk#.goog
- DNS ASK rn#########-15-161.a.free.pinggy.link
- ClassName: 'Edit' WindowName: ''
- '%WINDIR%\temp\explorer.exe' -p123
- '%LOCALAPPDATA%\explorer.exe'
- '%LOCALAPPDATA%\start.exe'
- '%APPDATA%\microsoft\windows\start menu\programs\startup\explorer.exe'
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Explorer.exe" /t REG_SZ /F /D "\"%LOCALAPPDATA%\Explorer.exe"\"