Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\winssvc.exe
- <SYSTEM32>\at.exe 20:28:28.73 /every:1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31 "%TEMP%\winssvc.exe"
- <SYSTEM32>\at.exe 20:28:26.45 /every:1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31 winssvc.exe
- <SYSTEM32>\tasklist.exe
- %TEMP%\p2xtmp-2816\auto\Win32\Win32.dll
- %TEMP%\p2xtmp-2816\auto\Fcntl\Fcntl.dll
- <Служебный элемент>
- %TEMP%\p2xtmp-2816\auto\Win32\Console\Console.dll
- <SYSTEM32>\winssvc.exe
- %TEMP%\winssvc.exe
- %TEMP%\p2xtmp-2816\auto\Socket\Socket.dll
- %TEMP%\p2xtmp-2816\auto\re\re.dll
- %TEMP%\p2xtmp-2816\auto\IO\IO.dll
- %TEMP%\p2xtmp-2816\p2x5122.dll
- %TEMP%\p2xtmp-2816\auto\Cwd\Cwd.dll
- %TEMP%\p2xtmp-2816\auto\mro\mro.dll
- %TEMP%\p2xtmp-2816\auto\B\B.dll
- %TEMP%\p2xtmp-2816\auto\List\Util\Util.dll
- 'localhost':8080
- 'ir#.#piran.net':8080
- 'bn##.##esntexist.org':8080
- DNS ASK ir#.#piran.net
- DNS ASK bn##.##esntexist.org