Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Test My Test svchose 4.0Windows Test My Test svchose 4.0] 'Start' = '00000002'
- '<SYSTEM32>\svchest.exe'
- '<Текущая директория>\ёЁЦъ№э·З·ЁІејю1.0.exe'
- <Текущая директория>\ёЁЦъ№э·З·ЁІејю1.0.exe
- <SYSTEM32>\svchest.exe
- <SYSTEM32>\PastPUQz0.sys
- <SYSTEM32>\BackInC.sys
- <Текущая директория>\ёЁЦъ№э·З·ЁІејю1.0.exe
- <SYSTEM32>\BackInC.sys
- <SYSTEM32>\PastPUQz0.sys
- 'cc#.#kdh.org':2012
- 'any':2012
- '21#.#5.30.196':2013
- 'a0#####23.blog.163.com':80
- a0#####23.blog.163.com/blog/static/21686601520131130058206/
- DNS ASK cc#.#kdh.org
- DNS ASK a0#####23.blog.163.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'