Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\usbsvc.exe
- %HOMEPATH%\Start Menu\Programs\Startup\usbsvc.exe
- %WINDIR%\Tasks\At1.job
- <SYSTEM32>\at.exe 0:58:37.76 /every:1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31 usbsvc.exe
- <SYSTEM32>\tasklist.exe
- %TEMP%\p2xtmp-2888\auto\Win32\Win32.dll
- %TEMP%\p2xtmp-2888\auto\Fcntl\Fcntl.dll
- <Служебный элемент>
- <SYSTEM32>\usbsvc.exe
- %TEMP%\p2xtmp-2888\auto\Socket\Socket.dll
- %TEMP%\p2xtmp-2888\auto\Win32\Console\Console.dll
- %TEMP%\p2xtmp-2888\auto\mro\mro.dll
- %TEMP%\p2xtmp-2888\auto\re\re.dll
- %TEMP%\p2xtmp-2888\auto\IO\IO.dll
- %TEMP%\p2xtmp-2888\p2x5122.dll
- %TEMP%\p2xtmp-2888\auto\B\B.dll
- %TEMP%\p2xtmp-2888\auto\List\Util\Util.dll
- %TEMP%\p2xtmp-2888\auto\Cwd\Cwd.dll
- 'we#####e.dyndns.info':8888
- 'we####he.dyndns.org':8888
- DNS ASK we#####e.dyndns.info
- DNS ASK we####he.dyndns.org