Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Service Host Process for Windows' = '%APPDATA%\System32\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Service Host Process for Windows' = '%APPDATA%\System32\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Host-process Windows (Rundll32.exe)' = '%APPDATA%\csrss.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Host-process Windows (Rundll32.exe)' = '%APPDATA%\csrss.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Client Server Runtime Process' = '%APPDATA%\csrss.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Client Server Runtime Process' = '%APPDATA%\csrss.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Host-process Windows (Rundll32.exe)' = '%APPDATA%\System32\rundll32.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Host-process Windows (Rundll32.exe)' = '%APPDATA%\System32\rundll32.exe'
- %APPDATA%\csrss.exe /first
- %APPDATA%\System32\svchost.exe
- %APPDATA%\System32\rundll32.exe
- %APPDATA%\csrss.exe
- %APPDATA%\System32\svchost.exe
- %APPDATA%\System32\rundll32.exe
- %APPDATA%\csrss.exe
- 'ma###era.com':7000
- '78.##9.121.80':7000
- DNS ASK ma###era.com
- ClassName: 'Indicator' WindowName: ''