Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft COM+ System Application' = '<LS_APPDATA>\EZWR\avp-updater.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<LS_APPDATA>\EZWR\avp-updater.exe' = '<LS_APPDATA>\EZWR\avp-updater.exe:*:Enabled:Microsoft COM+ System Application'
- '<LS_APPDATA>\EZWR\msclamwin.exe'
- '<LS_APPDATA>\EZWR\avp-updater.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "<LS_APPDATA>\EZWR\avp-updater.exe" "Microsoft COM+ System Application" ENABLE
- <LS_APPDATA>\EZWR\msclamwin.exe
- <LS_APPDATA>\EZWR\avp-updater.exe
- 'ma###get.com':80
- 'hi##mm.com':80
- ma###get.com/dse.php
- hi##mm.com/tire.php
- DNS ASK ma###get.com
- DNS ASK hi##mm.com
- ClassName: 'Class' WindowName: ''