Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WindowsEntServer2008] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WindowsEntServer2008] 'ImagePath' = '%WINDIR%\EntSver.exe'
- 'WindowsEntServer2008' %WINDIR%\EntSver.exe
- %TEMP%\ixp000.tmp\1q1.exe
- %WINDIR%\entsver.exe
- %WINDIR%\entsver.exe
- %TEMP%\ixp000.tmp\1q1.exe
- DNS ASK sh####nyun.vicp.cc
- '%TEMP%\ixp000.tmp\1q1.exe'
- '%WINDIR%\entsver.exe'
- '%TEMP%\ixp000.tmp\1q1.exe' ' (со скрытым окном)