Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Definder Extation' = '"%ProgramFiles%\Runtime\Runk80II3z6pjcMs63z5mX8w0mev8K903.exe" start'
- [HKLM\System\CurrentControlSet\Services\Terminator] 'ImagePath' = '%ALLUSERSPROFILE%\Driver\Driver_706.sys'
- 'Terminator' %ALLUSERSPROFILE%\Driver\Driver_706.sys
- %ProgramFiles%\runtime\runk80ii3z6pjcms63z5mx8w0mev8k903.exe
- %ALLUSERSPROFILE%\driver\driver_706.sys
- 'ip##pi.com':80
- '47.##9.197.97':30215
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- http://ip##pi.com/json/
- DNS ASK ip##pi.com
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%ProgramFiles%\runtime\runk80ii3z6pjcms63z5mx8w0mev8k903.exe' start