Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{1D476073-5E7F-AD41-B897-60D4A63F43C6}' = '"%APPDATA%\Idty\fefyla.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- '%APPDATA%\Idty\fefyla.exe'
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\tmpb91429c6.bat"
- <SYSTEM32>\cscript.exe
- [<HKCU>\Software\Microsoft\Windows Live Mail]
- [<HKCU>\Software\Microsoft\Internet Account Manager\Accounts]
- [<HKCU>\Software\Microsoft\Internet Account Manager]
- %TEMP%\tmpb91429c6.bat
- <LS_APPDATA>\kaalo.bey
- %APPDATA%\Idty\fefyla.exe
- '10#.#4.154.77':10640
- '18#.#4.169.226':19172
- '19#.#69.125.228':29902
- '70.##2.191.161':13503
- '78.##.114.73':10210
- '17#.#0.223.19':18883
- '81.##6.230.235':29447
- '99.#1.0.138':12952
- '99.##.164.217':10357
- '79.##5.239.10':10020
- '21#.#90.251.195':19899
- '75.##.141.163':23063
- '79.##8.49.198':27401
- '10#.#23.4.61':22313
- '75.#.222.103':11577
- '19#.#4.127.98':25549
- ClassName: 'Indicator' WindowName: ''