Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '989397932e4b6b5cfdbd374e593524d5' = '"%APPDATA%\Dev-pont.com" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '989397932e4b6b5cfdbd374e593524d5' = '"%APPDATA%\Dev-pont.com" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\989397932e4b6b5cfdbd374e593524d5.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\Dev-pont.com' = '%APPDATA%\Dev-pont.com:*:Enabled:Dev-pont.com'
- '%APPDATA%\Dev-pont.com'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\Dev-pont.com" "Dev-pont.com" ENABLE
- %APPDATA%\Dev-pont.com
- 'ar#####max.no-ip.org':1188
- DNS ASK ar#####max.no-ip.org
- ClassName: 'Indicator' WindowName: '(null)'