Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\system-1185576] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\system-1185576] 'ImagePath' = '"%ProgramFiles(x86)%\pcawhere\thinprobe.exe"'
- [<HKLM>\System\CurrentControlSet\Services\pcAnywhere] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\pcAnywhere] 'ImagePath' = '"%ProgramFiles(x86)%\pcawhere\thinprobe.exe"'
- 'system-1185576' "%ProgramFiles(x86)%\pcawhere\thinprobe.exe"
- 'system-1185576' %ProgramFiles(x86)%\pcawhere\thinprobe.exe
- 'pcAnywhere' "%ProgramFiles(x86)%\pcawhere\thinprobe.exe"
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\7z22df5218\thumb.db
- %TEMP%\7z22df5218\thinprobe.exe
- %TEMP%\7z22df5218\thinhostprobedll.dll
- %ProgramFiles(x86)%\pcawhere\config.ini
- %TEMP%\7z22df5218\thinprobe.exe в %ProgramFiles(x86)%\pcawhere\thinprobe.exe
- %TEMP%\7z22df5218\thinhostprobedll.dll в %ProgramFiles(x86)%\pcawhere\thinhostprobedll.dll
- %TEMP%\7z22df5218\thumb.db в %ProgramFiles(x86)%\pcawhere\thumb.db
- '13#.#80.208.225':443
- 'sk####ndonesia.com':443
- '13#.#80.208.225':443
- 'sk####ndonesia.com':443
- DNS ASK sk####ndonesia.com
- '%TEMP%\7z22df5218\thinprobe.exe'
- '%ProgramFiles(x86)%\pcawhere\thinprobe.exe'
- '%WINDIR%\syswow64\svchost.exe' -daemon' (со скрытым окном)
- '%WINDIR%\syswow64\svchost.exe' -daemon