Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '[EXPL0RER]' = '%WINDIR%\V3liek\QVMLIKE.exe'
- '<SYSTEM32>\net1.exe' stop sharedaccess
- '<SYSTEM32>\netsh.exe' firewall set opmode disable
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wscript.exe' "%WINDIR%\V3like.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\Fobeka.bat" "
- '<SYSTEM32>\net.exe' stop sharedaccess
- %WINDIR%\V3liek\QVMLIKE.exe
- %WINDIR%\Fobeka.bat
- %WINDIR%\V3like.vbs
- '67.##8.145.242':80
- 67.##8.145.242/kbs.exe