Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSeri] 'Start' = '00000002'
- '<SYSTEM32>\WinS.exe'
- '<SYSTEM32>\cmd.exe' /c c:\del.bat
- '<SYSTEM32>\net1.exe' start WinSeri
- '<SYSTEM32>\sc.exe' create WinSeri binpath= "<SYSTEM32>\WinS.exe" type= share start= auto displayname= "systei" depend= RPCSS/Tcpip/IPSec
- <SYSTEM32>\spoolsv.exe
- C:\bstemp.ini
- <SYSTEM32>\hz_WinS.shd
- C:\del.bat
- <SYSTEM32>\WinS.txt
- <SYSTEM32>\WinS.jpg
- <SYSTEM32>\hz_WinS.dll
- <SYSTEM32>\he.txt
- <SYSTEM32>\WinS.ini
- <SYSTEM32>\keyHook.dll
- %PROGRAM_FILES%\Internet Explorer\xiezai.cfg
- <SYSTEM32>\hz_WinS.dat
- %PROGRAM_FILES%\Internet Explorer\xiezai.cfg
- <SYSTEM32>\WinS.exe
- <SYSTEM32>\WinS.ini
- C:\bstemp.ini
- <SYSTEM32>\hz_WinS.dat
- <SYSTEM32>\he.txt в <SYSTEM32>\WinS.exe
- 'vi####e.3322.org':8760
- DNS ASK vi####e.3322.org
- ClassName: 'MS_WINHELP' WindowName: ''