Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{EA2V8NG1-42RB-A0BE-WU8R-4MWI3A40B0PJ}] 'StubPath' = '"%APPDATA%\Install\Host.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'windowsproxy' = '%APPDATA%\Install\Host.exe'
- '<LS_APPDATA>\Spoon\Sandbox\1.0.0.0\local\stubexe\0x44070691BBAF7FA4\Host.exe'
- %APPDATA%\Install\Host.exe
- <LS_APPDATA>\Spoon\Sandbox\1.0.0.0\xsandbox.bin.__tmp__
- <LS_APPDATA>\Spoon\Sandbox\1.0.0.0\local\stubexe\0x44070691BBAF7FA4\Host.exe.__tmp__ в <LS_APPDATA>\Spoon\Sandbox\1.0.0.0\local\stubexe\0x44070691BBAF7FA4\Host.exe
- <LS_APPDATA>\Spoon\Sandbox\1.0.0.0\xsandbox.bin.__tmp__ в <LS_APPDATA>\Spoon\Sandbox\1.0.0.0\xsandbox.bin
- 'an####337.zapto.org':1177
- 'an###.#337.zapto.org':3360
- 'st###.spoon.net':443
- 'an####337.zapto.org':25
- DNS ASK an###.#337.zapto.org
- DNS ASK an####337.zapto.org
- DNS ASK st###.spoon.net
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'