Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'LocalServicee' = '%APPDATA%\LocalServicee'
- <SYSTEM32>\tasks\localservicee
- %APPDATA%\microsoft\windows\start menu\programs\startup\localservicee.lnk
- %APPDATA%\localservicee
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\localservicee.log
- 'ip##pi.com':80
- 'SO#######RY-51505.portmap.host':51505
- http://ip##pi.com/line/?fi############
- DNS ASK ip##pi.com
- DNS ASK SO#######RY-51505.portmap.host
- '%APPDATA%\localservicee'
- '%WINDIR%\syswow64\schtasks.exe' /create /f /RL HIGHEST /sc minute /mo 1 /tn "LocalServicee" /tr "%APPDATA%\LocalServicee" (со скрытым окном)