Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\DNSSupport] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\DbSecuritySpt] 'Start' = '00000002'
- '%PROGRAM_FILES%\Windows Media Player\DNSProtection.exe'
- '%PROGRAM_FILES%\Windows Media Player\DNSSupport.exe'
- '%PROGRAM_FILES%\DbSecuritySpt\DbSecuritySpt.exe'
- '<SYSTEM32>\taskkill.exe' /F /IM Bill.exe
- '<SYSTEM32>\taskkill.exe' /F /IM svch0st.exe
- '<SYSTEM32>\taskkill.exe' /F /IM DbSecuritySpt.exe
- '<SYSTEM32>\taskkill.exe' /F /IM DNSProtection.exe
- '<SYSTEM32>\taskkill.exe' /F /IM DNSClient.exe
- %TEMP%\WER006b.dir00\DNSProtection.exe.mdmp
- %PROGRAM_FILES%\Windows Media Player\DNSSupport.exe
- %TEMP%\WER006b.dir00\DNSProtection.exe.hdmp
- %TEMP%\WER006b.dir00\manifest.txt
- %TEMP%\WER006b.dir00\appcompat.txt
- %PROGRAM_FILES%\DbSecuritySpt\svch0st.exe
- %PROGRAM_FILES%\DbSecuritySpt\DbSecuritySpt.exe
- %PROGRAM_FILES%\Windows Media Player\agony.exe
- %PROGRAM_FILES%\Windows Media Player\DNSProtection.exe
- %PROGRAM_FILES%\Windows Media Player\agony.sys
- '18#.#36.216.101':36000
- ClassName: '(null)' WindowName: '(null)'