Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winlogon' = '%APPDATA%\SubFolder\SubFolder\winlogon.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Winlogon' = '%APPDATA%\SubFolder\SubFolder\winlogon.exe'
- '%APPDATA%\microsoft\windows\templates\nsjjddqub.exe'
- winlogon.exe
- <SYSTEM32>\winlogon.exe
- <SYSTEM32>\dwm.exe
- %WINDIR%\explorer.exe
- <SYSTEM32>\taskhost.exe
- <SYSTEM32>\csrss.exe
- iexplore.exe
- firefox.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %APPDATA%\microsoft\windows\templates\nsjjddqub.exe
- %APPDATA%\subfolder\subfolder\winlogon.exe
- 'ni####xitupd.biz.pl':443
- DNS ASK ni####xitupd.biz.pl
- ClassName: 'CicLoaderWndClass' WindowName: ''
- '%APPDATA%\subfolder\subfolder\winlogon.exe'
- '<SYSTEM32>\smss.exe' 00000000 0000003c
- '<SYSTEM32>\csrss.exe' ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitializa...
- '<SYSTEM32>\winlogon.exe'