Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\DQUPYhWYBINE.lnk
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule action=allow profile=any protocol=any enable=yes direction=out name=Win2y2 program="<SYSTEM32>\wscript.exe"
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule action=allow profile=any protocol=any enable=yes direction=in name=Win2y2 program="<SYSTEM32>\wscript.exe"
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule profile=any name=Win2y2
- '%APPDATA%\KUJB.exe' "%APPDATA%\KUJBY.au3"
- '<SYSTEM32>\wscript.exe'
- <SYSTEM32>\wscript.exe
- %APPDATA%\KUJB.exe
- %APPDATA%\KUJBY.au3
- %TEMP%\aut1.tmp
- %TEMP%\pzutnqn
- %HOMEPATH%\AJxKhHlLJdGaomMP\KUJBY.au3
- %HOMEPATH%\AJxKhHlLJdGaomMP\KUJB.exe
- %TEMP%\pzutnqn
- %TEMP%\aut1.tmp
- %APPDATA%\KUJB.exe в %HOMEPATH%\AJxKhHlLJdGaomMP\KUJB.exe
- %APPDATA%\KUJBY.au3 в %HOMEPATH%\AJxKhHlLJdGaomMP\KUJBY.au3
- '18#.#1.158.123':1158
- ClassName: 'Shell_TrayWnd' WindowName: ''