Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\AarSvc_1f6f46] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\AarSvc_1f6f46] 'ImagePath' = 'cmd /c cd /d "<SYSTEM32>" && start "" "%ALLUSERSPROFILE%\DataExplorer\DataExplorer.exe"'
- 'AarSvc_1f6f46' cmd /c cd /d "<SYSTEM32>" && start "" "%ALLUSERSPROFILE%\DataExplorer\DataExplorer.exe"
- %WINDIR%\syswow64\backgroundtaskhost.exe
- Процесс drqa.exe, модуль USER32.dll
- %TEMP%\us investment portfolio strategy c组.pptx
- %LOCALAPPDATA%\kmfugom3\padding\data.dat
- %ALLUSERSPROFILE%\dataexplorer\dataexplorer.exe
- %ALLUSERSPROFILE%\dataexplorer\beqbxw32.dll
- %ALLUSERSPROFILE%\dataexplorer\cache.pmt
- '15#.#6.166.124':998
- '15#.#6.166.124':998
- '%ALLUSERSPROFILE%\dataexplorer\dataexplorer.exe'
- '%WINDIR%\explorer.exe' "%TEMP%\US Investment Portfolio Strategy C组.pptx"
- '<SYSTEM32>\perceptionsimulation\perceptionsimulationservice.exe'
- '%WINDIR%\syswow64\backgroundtaskhost.exe'