Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'UserInit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\taskmgr.com'
- [<HKLM>\SYSTEM\ControlSet001\Services\taskMgr] 'Start' = '00000002'
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- <SYSTEM32>\taskmgr.com
- 'sc#####r-001.zapto.org':8080
- DNS ASK sc#####r-001.zapto.org
- ClassName: 'SysListView32' WindowName: ''
- ClassName: '#32770' WindowName: ''
- ClassName: '18467-41' WindowName: ''