Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '51AA9A5C2F98879B' = '%ALLUSERSPROFILE%\YAMA\ServerDll.exe'
- <SYSTEM32>\tasks\yama
- [HKLM\SYSTEM\CurrentControlSet\Services\ServerDll] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\ServerDll] 'ImagePath' = '%ALLUSERSPROFILE%\YAMA\ServerDll.exe'
- 'ServerDll' %ALLUSERSPROFILE%\YAMA\ServerDll.exe
- %ALLUSERSPROFILE%\yama\serverdll.exe
- nul
- '11#.#89.212.72':6543
- '%ALLUSERSPROFILE%\yama\serverdll.exe'
- '%ALLUSERSPROFILE%\yama\serverdll.exe' -agent
- '<SYSTEM32>\cmd.exe' /C timeout /t 3 /nobreak > Nul & Del /f /q "<Полный путь к файлу>"
- '<SYSTEM32>\timeout.exe' /t 3 /nobreak