Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{9424D614-4115-A129-B9E9-B9872C616801}' = '"%APPDATA%\Geohq\mahoy.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\ctfmon.exe' = '<SYSTEM32>\ctfmon.exe:*:Enabled:ctfmon.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\explorer.exe' = '%WINDIR%\explorer.exe:*:Enabled:explorer.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\Geohq\mahoy.exe' = '%APPDATA%\Geohq\mahoy.exe:*:Enabled:mahoy.exe'
- '%APPDATA%\Geohq\mahoy.exe'
- <SYSTEM32>\ctfmon.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1406' = '00000000'
- %APPDATA%\Uwgiy\widyr.ety
- %TEMP%\tmp4b4b1ea1.bat
- %APPDATA%\Geohq\mahoy.exe
- 'es###siness.com':80
- es###siness.com/wp-content/themes/covertstorebuilder/css/plugin.dat
- DNS ASK es###siness.com
- ClassName: 'Indicator' WindowName: '(null)'