Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Services' = '<DRIVERS>\services.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Winlogon' = '<DRIVERS>\winlogon.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<DRIVERS>\winlogon.exe' = '<DRIVERS>\winlogon.exe:*:Enabled:.NET Framework'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<DRIVERS>\csrss.exe' = '<DRIVERS>\csrss.exe:*:Enabled:.NET Framework Updates'
- '<DRIVERS>\winlogon.exe' updated
- '<DRIVERS>\services.exe' 2924
- '<DRIVERS>\winlogon.exe'
- '<DRIVERS>\csrss.exe' -winsock
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "<DRIVERS>\winlogon.exe" ".NET Framework" ENABLE
- '<SYSTEM32>\regsvr32.exe' MSWINSCK.OCX /s
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "<DRIVERS>\csrss.exe" ".NET Framework Updates" ENABLE
- <SYSTEM32>\MSWINSCK.OCX
- <DRIVERS>\services.exe
- <DRIVERS>\winlogon.exe
- <DRIVERS>\csrss.exe
- <DRIVERS>\csrss.exe
- 'tr##.no-ip.org':27047
- 'www.ho##ip.info':80
- 'www.cz###ution.com':80
- www.ho##ip.info/
- www.cz###ution.com/download/MSWINSCK.OCX
- DNS ASK tr##.no-ip.org
- DNS ASK www.ho##ip.info
- DNS ASK www.cz###ution.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'