Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\124603] 'ImagePath' = '<Текущая директория>\124603.sys'
- <SYSTEM32>\svchost.exe
- <Текущая директория>\124603.sys
- <SYSTEM32>\124603.sys
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\224105029201374544314[1]
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\224105029201374544314[1]
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\224105029201374544314_[1]
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\224105029201374544314[1]
- <Текущая директория>\124603.sys
- <SYSTEM32>\124603.sys
- 'hs####.blog.163.com':80
- http://hs####.blog.163.com/blog/static/224105029201374544314/
- http://hs####.blog.163.com/blog/static/224105029201374544314//
- DNS ASK hs####.blog.163.com
- '<SYSTEM32>\svchost.exe'