Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'eac726c' = '%APPDATA%\Roaming\eac726c.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '*ac726c' = '%APPDATA%\Roaming\eac726c.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'eac726' = 'C:\eac726c\eac726c.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '*ac726' = 'C:\eac726c\eac726c.exe'
- Компонент восстановления системы (SR)
- '<SYSTEM32>\bcdedit.exe' /set {default} bootstatuspolicy ignoreallfailures
- '<SYSTEM32>\vssvc.exe'
- '<SYSTEM32>\svchost.exe' -k swprv
- '<SYSTEM32>\bcdedit.exe' /set {default} recoveryenabled No
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\svchost.exe' netsvcs
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet
- <SYSTEM32>\svchost.exe
- %WINDIR%\explorer.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eac726c.exe
- %APPDATA%\Roaming\eac726c.exe
- C:\eac726c\eac726c.exe
- 'se###abboy.com':80
- DNS ASK se###abboy.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'