Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '%USERNAME%' = '%HOMEPATH%\%USERNAME%.exe /i'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\explorer.exe' = '%WINDIR%\explorer.exe:*:Enabled:ENABLE'
- %HOMEPATH%\%USERNAME%.exe /i
- <SYSTEM32>\netsh.exe firewall set allowedprogram "%WINDIR%\Explorer.EXE" ENABLE
- <SYSTEM32>\wbem\wmiprvse.exe
- %WINDIR%\Explorer.EXE
- %HOMEPATH%\%USERNAME%.exe
- %HOMEPATH%\%USERNAME%.exe
- '21#.#45.223.34':80
- 21#.#45.223.34/40E8001431313030303030303030303030303030303031306C0000014A66000000007600000642EB00053059453975
- ClassName: 'Indicator' WindowName: ''