Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'atualizar' = '<SYSTEM32>\Windows\taskhost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows' = '<SYSTEM32>\Windows\taskhost.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{0W7B4V3A-5LWD-77D5-S6RY-1L16RQCJCG7N}] 'StubPath' = '<SYSTEM32>\Windows\taskhost.exe restart'
- [<HKLM>\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{0W7B4V3A-5LWD-77D5-S6RY-1L16RQCJCG7N}] 'StubPath' = '<SYSTEM32>\Windows\taskhost.exe'
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\windows\taskhost.exe
- %WINDIR%\syswow64\windows\taskhost.exe
- 'sp####1.ddns.net':2000
- DNS ASK sp####1.ddns.net
- '%WINDIR%\syswow64\svchost.exe'