Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '99a67443d39b8481435f648cbd464c7c' = '"%TEMP%\server.scr" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '99a67443d39b8481435f648cbd464c7c' = '"%TEMP%\server.scr" ..'
- '%TEMP%\server.scr' /S
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\server.scr" "server.scr" ENABLE
- %TEMP%\server.scr
- 'localhost':288
- ClassName: 'Indicator' WindowName: ''