Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'UserInit' = '<SYSTEM32>\userinit.exe,%HOMEPATH%\My Documents\MSDCSC\msdcsc.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MicroUpdate' = '%HOMEPATH%\My Documents\MSDCSC\msdcsc.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\DRCTROY.exe' = '%TEMP%\DRCTROY.exe:*:Enabled:DRCTROY.exe'
- '%TEMP%\DRCTROY.exe'
- '%HOMEPATH%\My Documents\MSDCSC\msdcsc.exe'
- '%TEMP%\Exe To Base 64 By hackers DZ.exe'
- '%TEMP%\dark.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\DRCTROY.exe" "DRCTROY.exe" ENABLE
- '<SYSTEM32>\attrib.exe' "%HOMEPATH%\Local Settings\Temp" +s +h
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\attrib.exe' "%TEMP%\dark.exe" +s +h
- <SYSTEM32>\notepad.exe
- %TEMP%\DRCTROY.exe
- %HOMEPATH%\My Documents\MSDCSC\msdcsc.exe
- %TEMP%\Exe To Base 64 By hackers DZ.exe
- %TEMP%\dark.exe
- %TEMP%\dark.exe
- 'uk##.zapto.org':666
- 'uk##.zapto.org':1604
- 'uk####k.linkpc.net':666
- 'uk####k.linkpc.net':1604
- DNS ASK uk##.zapto.org
- DNS ASK uk####k.linkpc.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''