Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'd4645020c1113af1434b1af8f5776a0c' = '"%TEMP%\miccrosaft.exe" ..'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'd4645020c1113af1434b1af8f5776a0c' = '"%TEMP%\miccrosaft.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\d4645020c1113af1434b1af8f5776a0c.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\miccrosaft.exe" "miccrosaft.exe" ENABLE
- %TEMP%\miccrosaft.exe
- DNS ASK ro#####moud.casacam.net
- '%TEMP%\miccrosaft.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\miccrosaft.exe" "miccrosaft.exe" ENABLE (со скрытым окном)