Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AppRt09e9' = '%LOCALAPPDATA%\AppRt09e9\apprt09e9.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AppSvc09e9' = '%LOCALAPPDATA%\Programs\09e9\svc09e9.exe'
- <SYSTEM32>\fontdrvhost.exe
- nul
- %LOCALAPPDATA%\apprt09e9\apprt09e9.exe
- %LOCALAPPDATA%\programs\09e9\svc09e9.exe
- '20#.#94.54.131':6543
- '%LOCALAPPDATA%\apprt09e9\apprt09e9.exe'
- '%LOCALAPPDATA%\programs\09e9\svc09e9.exe'
- '%LOCALAPPDATA%\apprt09e9\apprt09e9.exe' (со скрытым окном)
- '%LOCALAPPDATA%\programs\09e9\svc09e9.exe' (со скрытым окном)