Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\LmHost] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\LmHost] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\LmHost\Parameters] 'ServiceDLL' = '<SYSTEM32>\semfpBsW.dll'
- 'LmHost' <SYSTEM32>\svchost.exe -k netsvcs
- %WINDIR%\syswow64\hkpriteuia.ini
- %WINDIR%\syswow64\semfpbsw.dll
- %WINDIR%\syswow64\hkpriteuia.del
- DNS ASK mi##.3322.org