Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsMs NT Process Services' = '"%WINDIR%\windowshostservice.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsMs NT Process Services' = '"%WINDIR%\system\winlogon.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsMs NT Process Host Service' = '"%WINDIR%\system\winlogon.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsMs NT Process Services' = '"%WINDIR%\windowshostservice.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsMs NT Process Host Service' = '"%WINDIR%\windowshostservice.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsMs NT Process Host Service' = '"%WINDIR%\system\winlogon.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsMs NT Process Host Service' = '"%WINDIR%\windowshostservice.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsMs NT Process Services' = '"%WINDIR%\system\winlogon.exe"'
- %WINDIR%\windowshostservice.exe
- %WINDIR%\windowsmssystem.sys
- %WINDIR%\windowshostservice.exe
- %TEMP%\~DFAA03.tmp
- %TEMP%\~DF786B.tmp
- %TEMP%\~DFD100.tmp
- %TEMP%\~DF3B25.tmp
- '67.##5.160.76':5001
- DNS ASK vc#.##.#ip.dcn.yahoo.com
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Indicator' WindowName: ''