Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\system-1105235] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\system-1105235] 'ImagePath' = '%WINDIR%\pcawhere\thinprobe.exe'
- [<HKLM>\System\CurrentControlSet\Services\pcAnywhere] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\pcAnywhere] 'ImagePath' = '%WINDIR%\pcawhere\thinprobe.exe'
- 'system-1105235' %WINDIR%\pcawhere\thinprobe.exe
- 'pcAnywhere' %WINDIR%\pcawhere\thinprobe.exe
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\7z056469f0\thumb.db
- %TEMP%\7z056469f0\thinprobe.exe
- %TEMP%\7z056469f0\thinhostprobedll.dll
- %WINDIR%\pcawhere\config.ini
- %TEMP%\7z056469f0\thinprobe.exe в %WINDIR%\pcawhere\thinprobe.exe
- %TEMP%\7z056469f0\thinhostprobedll.dll в %WINDIR%\pcawhere\thinhostprobedll.dll
- %TEMP%\7z056469f0\thumb.db в %WINDIR%\pcawhere\thumb.db
- '<LOCALNET>.4.26':443
- '%TEMP%\7z056469f0\thinprobe.exe'
- '%WINDIR%\pcawhere\thinprobe.exe'
- '%WINDIR%\syswow64\svchost.exe' -daemon