Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ATP 0' = '<SYSTEM32>\lderiver.exe 0'
- \Device\LanmanRedirector\CRNJEUFU*\MAILSLOT\NET\NETLOGON
- %WINDIR%\system\lderiver.exe
- <SYSTEM32>\lderiver.exe
- <SYSTEM32>\lderiver.exe
- 'dl.#####oxusercontent.com':443
- 'wp#d':80
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK dl.#####oxusercontent.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''