Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GUI Starter' = '%APPDATA%\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Sound Service' = '%APPDATA%\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'GUI Starter' = '%APPDATA%\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Firewall' = '%APPDATA%\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'Windows Automatic Update' = '%APPDATA%\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Windows Desktop' = '%APPDATA%\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Recycle Utility' = '%APPDATA%\svchost.exe'
- %APPDATA%\svchost.exe
- bdagent.exe
- ekrn.exe
- smc.exe
- Drwebupw.exe
- outpost.exe
- fsav32.exe
- AVP.EXE
- zlclient.exe
- %APPDATA%\svchost.exe
- %APPDATA%\svchost.exe
- 'oh##.###vegotshemale.info':7777
- 'an#####scool.no-ip.biz':1337
- DNS ASK oh##.###vegotshemale.info
- DNS ASK an#####scool.no-ip.biz
- ClassName: '' WindowName: 'BitDefender Firewall Alert'
- ClassName: '' WindowName: 'Windows Security Alert'
- ClassName: 'Indicator' WindowName: ''