Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'd43f2cf11bf43aedb6170a7ae5f4dad8' = '"%TEMP%\srver.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'd43f2cf11bf43aedb6170a7ae5f4dad8' = '"%TEMP%\srver.exe" ..'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\srver.exe' = '%TEMP%\srver.exe:*:Enabled:srver.exe'
- '%TEMP%\srver.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\srver.exe" "srver.exe" ENABLE
- %TEMP%\srver.exe
- 'ma####xp.no-ip.biz':1177
- DNS ASK ma####xp.no-ip.biz
- ClassName: 'Indicator' WindowName: '(null)'