Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '7678a12' = '%APPDATA%\Roaming\7678a12.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '*678a12' = '%APPDATA%\Roaming\7678a12.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '7678a1' = 'C:\7678a12\7678a12.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '*678a1' = 'C:\7678a12\7678a12.exe'
- Компонент восстановления системы (SR)
- '<SYSTEM32>\vssvc.exe'
- '<SYSTEM32>\bcdedit.exe' /set {default} bootstatuspolicy ignoreallfailures
- '<SYSTEM32>\svchost.exe' -k swprv
- '<SYSTEM32>\bcdedit.exe' /set {default} recoveryenabled No
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\svchost.exe' netsvcs
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet
- <SYSTEM32>\svchost.exe
- %WINDIR%\explorer.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7678a12.exe
- %APPDATA%\Roaming\7678a12.exe
- C:\7678a12\7678a12.exe
- 'ba####utsnil.com':80
- DNS ASK ba####utsnil.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'