Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\MYSQL] 'ImagePath' = '%CommonProgramFiles%\Microsoft Shared\Speech\sapi.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\MYSQL] 'Start' = '00000002'
- '%CommonProgramFiles%\Microsoft Shared\Speech\sapi.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\ICEHUF.bat
- '<SYSTEM32>\svchost.exe' 70408
- <SYSTEM32>\svchost.exe
- %TEMP%\ICEHUF.bat
- %CommonProgramFiles%\Microsoft Shared\Speech\sapi.exe
- %CommonProgramFiles%\Microsoft Shared\Speech\sapi.exe
- '70###.rhelper.com':2016
- DNS ASK 70###.rhelper.com