Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = ',%TEMP%\4424ymg.dll'
- C:\WowMatris.exe
- C:\WowMatrix.exe
- <SYSTEM32>\cmd.exe /c ""%TEMP%\a.baT" "
- %TEMP%\4424ymg.dll
- %TEMP%\a.baT
- <LS_APPDATA>\._Revolution_\._88e6680f0002000000004673000000005e92903c86e5058d003af8fdf1ba6dc5_00000998.pid
- C:\WowMatrix.exe
- C:\WowMatris.exe
- C:\WowMatris.exe
- 'sw#####e.wowmatrix.com':80
- sw#####e.wowmatrix.com/r/1350978268245/netstart.gz
- DNS ASK sw#####e.wowmatrix.com
- ClassName: 'WindowsForms10.Window.8.app3' WindowName: ''
- ClassName: 'Turbine Device Class' WindowName: ''
- ClassName: 'GxWindowClassD3d' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''