Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\9fcacb2d] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\9fcacb2d] 'ImagePath' = '%ALLUSERSPROFILE%\9fcacb2db\b9fcacb2d.exe'
- '9fcacb2d' %ALLUSERSPROFILE%\9fcacb2db\b9fcacb2d.exe
- %ALLUSERSPROFILE%\9fcacb2db\b9fcacb2d.exe
- %ALLUSERSPROFILE%\9fcacb2db\rcdll.dll
- %ALLUSERSPROFILE%\9fcacb2db\instsrv.exe
- %ALLUSERSPROFILE%\9fcacb2db\wwwww\wwwww.lnk
- %ALLUSERSPROFILE%\9fcacb2db\instsrv.exe
- %ALLUSERSPROFILE%\9fcacb2db\wwwww\wwwww.lnk
- http://aa###########77.cos.ap-beijing-fsi.myqcloud.com/wjm.txt
- http://aa###########77.cos.ap-beijing-fsi.myqcloud.com/exe.jpg
- http://aa###########77.cos.ap-beijing-fsi.myqcloud.com/dll.jpg
- http://aa###########77.cos.ap-beijing-fsi.myqcloud.com/instsrv.exe
- DNS ASK aa###########77.cos.ap-beijing-fsi.myqcloud.com
- DNS ASK 6.####92929.cool
- DNS ASK 6.####14114114.icu
- ClassName: '' WindowName: '%ALLUSERSPROFILE%\9fcacb2db\wwwww'
- ClassName: '' WindowName: 'wwwww'
- ClassName: 'ShellTabWindowClass' WindowName: ''
- ClassName: 'DUIViewWndClassName' WindowName: ''
- ClassName: 'DirectUIHWND' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- '%ALLUSERSPROFILE%\9fcacb2db\instsrv.exe' 9fcacb2d %ALLUSERSPROFILE%\9fcacb2db\b9fcacb2d.exe