Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '*LoopholeTu' = 'rundll32.exe %APPDATA%\TorretIff.dll,EntryPoint'
- %WINDIR%\syswow64\regsvr32.exe
- %APPDATA%\torretiff.dll
- DNS ASK pa#####n.duckdns.org
- '%WINDIR%\syswow64\regsvr32.exe'
- '%WINDIR%\syswow64\cmd.exe' /C reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "*LoopholeTu" /t REG_SZ /d "rundll32.exe %APPDATA%\TorretIff.dll",EntryPoint /f & exit
- '%WINDIR%\syswow64\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "*LoopholeTu" /t REG_SZ /d "rundll32.exe %APPDATA%\TorretIff.dll",EntryPoint /f