Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\FastUserSwitchingCompatibility] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\FastUserSwitchingCompatibility] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility\Parameters] 'ServiceDll' = '<SYSTEM32>\FastUserSwitchingCompatibilityex.dll'
- 'AeLookupSvc' <SYSTEM32>\svchost.exe -k netsvcs
- 'CertPropSvc' <SYSTEM32>\svchost.exe -k netsvcs
- 'SCPolicySvc' <SYSTEM32>\svchost.exe -k netsvcs
- 'lanmanserver' <SYSTEM32>\svchost.exe -k netsvcs
- 'gpsvc' <SYSTEM32>\svchost.exe -k netsvcs
- 'AudioSrv' <SYSTEM32>\svchost.exe -k netsvcs
- 'FastUserSwitchingCompatibility' <SYSTEM32>\svchost.exe -k netsvcs
- 'tunnel' system32\DRIVERS\tunnel.sys
- %TEMP%\%d_res.tmp
- %WINDIR%\syswow64\fastuserswitchingcompatibilityex.dll
- %TEMP%\%d_res.tmp в %WINDIR%\syswow64\fastuserswitchingcompatibilityex.dll
- DNS ASK xi#####gxue.3322.org