Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\fastuserswitchingcompatibility] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\fastuserswitchingcompatibility] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\SYSTEM\CurrentControlSet\seRviCes\fastuserswitchingcompatibility\parameters] 'seRViCEDLl' = '<SYSTEM32>\smrmq.pdf'
- 'fastuserswitchingcompatibility' <SYSTEM32>\svchost.exe -k netsvcs
- %TEMP%\1353168.txt
- %TEMP%\1353168.txt в %WINDIR%\syswow64\smrmq.pdf
- DNS ASK bj.##koe.com
- DNS ASK ba##u.com