Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'Windows Session Manager' = '"%PROGRAMDATA%\services\csrss.exe"'
- %PROGRAMDATA%\services\csrss.exe
- %TEMP%\9p2i8f~1\state.tmp
- %TEMP%\9p2i8f~1\unverified-microdesc-consensus.tmp
- %TEMP%\9p2i8f~1\cached-certs.tmp
- %TEMP%\9p2i8f~1\cached-microdesc-consensus.tmp
- %PROGRAMDATA%\services\csrss.exe
- %TEMP%\9p2i8f~1\unverified-microdesc-consensus
- %TEMP%\9p2i8f~1\state.tmp в %TEMP%\9p2i8f~1\state
- %TEMP%\9p2i8f~1\unverified-microdesc-consensus.tmp в %TEMP%\9p2i8f~1\unverified-microdesc-consensus
- %TEMP%\9p2i8f~1\cached-certs.tmp в %TEMP%\9p2i8f~1\cached-certs
- %TEMP%\9p2i8f~1\cached-microdesc-consensus.tmp в %TEMP%\9p2i8f~1\cached-microdesc-consensus
- 'localhost':49160
- '86.#9.21.38':443
- '19#.#09.206.212':443