Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'Windows Session Manager' = '"%ALLUSERSPROFILE%\services\csrss.exe"'
- %ALLUSERSPROFILE%\services\csrss.exe
- %TEMP%\9p2i8f~1\state.tmp
- %TEMP%\9p2i8f~1\unverified-microdesc-consensus.tmp
- %TEMP%\9p2i8f~1\cached-certs.tmp
- %TEMP%\9p2i8f~1\cached-microdesc-consensus.tmp
- %TEMP%\9p2i8f~1\cached-microdescs.new
- %ALLUSERSPROFILE%\services\csrss.exe
- %TEMP%\9p2i8f~1\unverified-microdesc-consensus
- %TEMP%\9p2i8f~1\state
- %TEMP%\9p2i8f~1\state.tmp в %TEMP%\9p2i8f~1\state
- %TEMP%\9p2i8f~1\unverified-microdesc-consensus.tmp в %TEMP%\9p2i8f~1\unverified-microdesc-consensus
- %TEMP%\9p2i8f~1\cached-certs.tmp в %TEMP%\9p2i8f~1\cached-certs
- %TEMP%\9p2i8f~1\cached-microdesc-consensus.tmp в %TEMP%\9p2i8f~1\cached-microdesc-consensus
- %TEMP%\9p2i8f~1\state.tmp
- %TEMP%\9p2i8f~1\state
- http://wh#####yipaddress.com/
- http://wh###myip.net/
- DNS ASK wh#####yipaddress.com
- DNS ASK wh###myip.net