Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Service Host Process for Windows' = '%APPDATA%\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Service Host Process for Windows' = '%APPDATA%\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Host-process Windows (Rundll32.exe)' = '%APPDATA%\System32\csrss.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Host-process Windows (Rundll32.exe)' = '%APPDATA%\System32\csrss.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Client Server Runtime Process' = '%APPDATA%\System32\csrss.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Client Server Runtime Process' = '%APPDATA%\System32\csrss.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Host-process Windows (Rundll32.exe)' = '%APPDATA%\System32\rundll32.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Host-process Windows (Rundll32.exe)' = '%APPDATA%\System32\rundll32.exe'
- '%APPDATA%\System32\csrss.exe'
- %APPDATA%\svchost.exe
- %APPDATA%\System32\rundll32.exe
- %APPDATA%\System32\csrss.exe
- %APPDATA%\svchost.exe
- %APPDATA%\System32\rundll32.exe
- %APPDATA%\System32\csrss.exe
- '21#.#3.3.184':7000
- '94.##0.191.201':25
- 'sm##.live.com':25
- DNS ASK sm##.mail.ru
- DNS ASK sm##.live.com
- ClassName: 'Indicator' WindowName: '(null)'