Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'systemupdate' = '%TEMP%\kwcs.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- '%TEMP%\kwcs.exe'
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v "EnableFirewall" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\cmd.exe' /c %HOMEPATH%\Local Settings\Temprunner.bat
- %TEMP%\img1.bmp
- %TEMP%\img2.bmp
- %TEMP%\img0.bmp
- %HOMEPATH%\Local Settings\Temprunner.bat
- %TEMP%\kwcs.exe
- 'ft#.#rivehq.com':21
- 'localhost':1035
- DNS ASK ft#.#rivehq.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'