Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\aeotii] 'Start' = '00000002'
- '<SYSTEM32>\winntap.exe'
- '%APPDATA%\sconwin.exe'
- '<SYSTEM32>\winntap.exe' (загружен из сети Интернет)
- '<SYSTEM32>\sc.exe' create aeotii binPath= "<SYSTEM32>\winntap.exe" start= auto Displayname= "Software aeoti" type= own
- '<SYSTEM32>\sc.exe' start aeotii
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v scowin /t REG_SZ /d %APPDATA%\sconwin.exe /f
- '<SYSTEM32>\net1.exe' user /domain
- '<SYSTEM32>\ipconfig.exe' /all
- %APPDATA%\get.txt
- <SYSTEM32>\winntap.exe
- %APPDATA%\sconwin.exe
- %APPDATA%\user.txt
- %APPDATA%\sconwin.exe
- 'www.ci####-support.com':80
- 'ci#######.citrix-support.com':80
- www.ci####-support.com/citrix-setup/winsisx.exe
- DNS ASK www.ci####-support.com
- DNS ASK ci#######.citrix-support.com