Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\NWCWorkstation\Parameters] 'ServiceDll' = '<SYSTEM32>\NWCWorkstation.txt'
- [<HKLM>\SYSTEM\ControlSet001\Services\NWCWorkstation] 'ImagePath' = '<SYSTEM32>\SVCHOST.EXE -K NETSVCS'
- [<HKLM>\SYSTEM\ControlSet001\Services\NWCWorkstation] 'Start' = '00000002'
- '<SYSTEM32>\taskkill.exe' /f /t /im RSTray.exe
- %TEMP%\2016 6162057 1_wwhhmm.TEMP
- <SYSTEM32>\NWCWorkstation.txt
- %TEMP%\2016 6162057 1_wwhhmm.TEMP в <SYSTEM32>\NWCWorkstation.txt
- 'nw###8.3322.org':1598
- DNS ASK nw###8.3322.org
- ClassName: '' WindowName: ''