Техническая информация
- %WINDIR%\Tasks\SA.DAT
- '<SYSTEM32>\svchost.exe' -k netsvcs
- '<SYSTEM32>\dumprep.exe' 1128 -dm 7 7 %WINDIR%\PCHealth\ErrorRep\UserDumps\svchost.exe.20130628-012438-00.hdmp 16325836412032028
- '<SYSTEM32>\dumprep.exe' 1128 -dm 7 7 %WINDIR%\PCHealth\ErrorRep\UserDumps\svchost.exe.20130628-012438-00.mdmp 16325836412032028
- %WINDIR%\pchealth\ERRORREP\UserDumps\svchost.exe.20130628-012438-00.hdmp
- '0.#.0.55':445
- '0.#.0.34':445
- '0.#.0.50':445
- '0.#.0.38':445
- '0.#.0.57':445
- '0.#.0.32':445
- '0.#.0.36':445
- '0.#.0.53':445
- '0.#.0.63':445
- '0.#.0.29':445
- '0.#.0.52':445
- '0.#.0.54':445
- '0.#.0.58':445
- '0.#.0.46':445
- '0.#.0.42':445
- '0.#.0.51':445
- '0.#.0.39':445
- '0.#.0.37':445
- '0.#.0.35':445
- '0.#.0.33':445
- '0.#.0.62':445
- '0.#.0.4':139
- '0.#.0.3':139
- '0.#.0.59':445
- '0.#.0.41':445
- '0.#.0.45':445
- '0.#.0.44':445
- '0.#.0.48':445
- '0.#.0.49':445
- '0.#.0.47':445
- '0.#.0.30':445
- '0.#.0.40':445
- '0.#.0.61':445
- '0.#.0.31':445
- '0.#.0.11':445
- '0.#.0.12':445
- '0.#.0.5':445
- '0.#.0.9':445
- '0.#.0.20':445
- '0.#.0.19':445
- '0.#.0.13':445
- '0.#.0.1':139
- '0.#.0.6':445
- '0.#.0.2':445
- '0.#.0.4':445
- 'xy#.#ulthar.biz':80
- '0.#.0.1':445
- '0.#.0.10':445
- '0.#.0.7':445
- '0.#.0.3':445
- '0.#.0.8':445
- '0.#.0.14':445
- '0.#.0.26':445
- '0.#.0.18':445
- '0.#.0.28':445
- '0.#.0.60':445
- '0.#.0.56':445
- '0.#.0.2':139
- '0.#.0.43':445
- '0.#.0.15':445
- '0.#.0.27':445
- '0.#.0.21':445
- '0.#.0.22':445
- '0.#.0.24':445
- '0.#.0.17':445
- '0.#.0.23':445
- '0.#.0.25':445
- '0.#.0.16':445
- DNS ASK xy#.#ulthar.biz