Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Temp' = 'cmd /c type %TEMP%\Temp.txt | cmd'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'Mswrd' = '%APPDATA%\svhost.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{88DU4BYL-1DR2-8N6T-HR32-NS46F381DF71}] 'StubPath' = '"%APPDATA%\svhost.exe"'
- svhost.exe
- %APPDATA%\svhost.exe
- %TEMP%\temp.txt
- %APPDATA%\.ighijklio
- %APPDATA%\.ighijklio
- 'localhost':3360
- '98.##3.144.239':6018
- '%APPDATA%\svhost.exe'
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "Temp" /d "cmd /c type "%TEMP%\Temp.txt" | cmd"