Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Bcdefg] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Bcdefg] 'ImagePath' = '%WINDIR%\svchost.exe'
- 'Bcdefg' %WINDIR%\svchost.exe
- %WINDIR%\syswow64\nslookup.exe
- %WINDIR%\qq.exe
- %WINDIR%\svchost.exe
- %WINDIR%\svchost.exe
- %WINDIR%\qq.exe в %TEMP%\[4df8afc3ea0e42163b1bc98de50ccb74]
- %WINDIR%\svchost.exe в %WINDIR%\syswow64\1069995.bak
- %WINDIR%\qq.exe
- '49.##2.144.22':6875
- ClassName: 'DiDaSG' WindowName: ''
- ClassName: 'DiDaGrid' WindowName: ''
- ClassName: 'DiDaViewCtrl' WindowName: ''
- ClassName: 'ConsoleWindowClass' WindowName: ''
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- '%WINDIR%\qq.exe'
- '%WINDIR%\svchost.exe'
- '%WINDIR%\qq.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\nslookup.exe' ' (со скрытым окном)
- '%WINDIR%\svchost.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\nslookup.exe'