Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'svchost.exe' = '<SYSTEM32>\dllcache\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'svchost.exe' = '<SYSTEM32>\dllcache\svchost.exe'
- <SYSTEM32>\dllcache\svchost.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\csrss.exe' = '%TEMP%\csrss.exe:*:Enabled:DNS'
- %TEMP%\csrss.exe
- <SYSTEM32>\cmd.exe /c %TEMP%\svchcst.bat
- <SYSTEM32>\dllcache\cmd.exe /c ren "%TEMP%\csrss.exe" ~ZA3O4D.tmp
- <SYSTEM32>\dllcache\svchost.exe
- %TEMP%\svchcst.bat
- %TEMP%\csrss.exe
- %TEMP%\csrss.exe в %TEMP%\~ZA3O4D.tmp
- DNS ASK it#.##player.net