Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\devenum53b5] 'Start' = '00000002'
- '<SYSTEM32>\rundll32.exe' "%CommonProgramFiles%\Microsoft Shared\MSInfo\devenum53b5.dll",ServiceBoot
- '<SYSTEM32>\wscript.exe' "%TEMP%\5e44_5a2a.vbs" //B //Nologo
- %CommonProgramFiles%\Microsoft Shared\MSInfo\RCX2.tmp
- %CommonProgramFiles%\Microsoft Shared\MSInfo\devenum53b5.ini
- %TEMP%\5e44_5a2a.vbs
- %TEMP%\3d68_4b55.dll
- %TEMP%\RCX1.tmp
- %CommonProgramFiles%\Microsoft Shared\MSInfo\devenum53b5.dll
- %TEMP%\5e44_5a2a.vbs
- %CommonProgramFiles%\Microsoft Shared\MSInfo\devenum53b5.ini
- %TEMP%\3d68_4b55.dll
- %CommonProgramFiles%\Microsoft Shared\MSInfo\devenum53b5.dll
- %CommonProgramFiles%\Microsoft Shared\MSInfo\RCX2.tmp в %CommonProgramFiles%\Microsoft Shared\MSInfo\devenum53b5.dll
- %TEMP%\RCX1.tmp в %TEMP%\3d68_4b55.dll
- 'ch###.guarkamt.com':443
- DNS ASK ch###.guarkamt.com
- ClassName: 'Shell_TrayWnd' WindowName: ''