Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WindowsÇý¶¯ÏµÍ³] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WindowsÇý¶¯ÏµÍ³] 'ImagePath' = '<SYSTEM32>\svchost.exe -k "WindowsÇý¶¯ÏµÍ³"'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\WindowsÇý¶¯ÏµÍ³\Parameters] 'ServiceDll' = '<SYSTEM32>\1215528.jpg'
- 'WindowsÇý¶¯ÏµÍ³' <SYSTEM32>\svchost.exe -k "WindowsÇý¶¯ÏµÍ³"
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %WINDIR%\syswow64\1215528.jpg
- %WINDIR%\syswow64\ini.ini
- %WINDIR%\syswow64\windowsГ§ГЅВ¶ВЇГЇВµГВі.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\1216480.bak
- 'nb##.f3322.net':4433
- DNS ASK xu###o999.com
- DNS ASK nb##.f3322.net
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\syswow64\windowsГ§ГЅВ¶ВЇГЇВµГВі.exe' "<SYSTEM32>\1215528.jpg",MainInstall
- '%WINDIR%\syswow64\svchost.exe' -k "WindowsÇý¶¯ÏµÍ³"