Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\ServiceHelp] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ServiceHelp] 'ImagePath' = '<SYSTEM32>\svchost.exe -k ServiceGroupEx'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\ServiceHelp\Parameters\] 'ServiceDll' = '%WINDIR%\SvcHelp.dll'
- 'ServiceHelp' <SYSTEM32>\svchost.exe -k ServiceGroupEx
- %WINDIR%\svchelp.dll
- %WINDIR%\svcdate.exe
- %WINDIR%\help.exe
- %WINDIR%\svcdate.exe
- %WINDIR%\svchelp.dll
- %WINDIR%\svchelp.dll
- 'he##.88us.cc':5058
- 'ud.##u456.top':80
- 'he##.88us.cc':80
- '1.##us.cc':5059
- http://ud.##u456.top/SvcDate.exe
- http://ud.##u456.top/help.exe
- http://ud.##u456.top/SvcHelp.dll
- 'he##.88us.cc':5058
- DNS ASK he##.88us.cc
- DNS ASK ud.##u456.top
- DNS ASK 1.##us.cc
- '%WINDIR%\svcdate.exe'
- '%WINDIR%\help.exe'
- '%WINDIR%\syswow64\net.exe' start ServiceHelp' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c del %WINDIR%\SvcDate.exe' (со скрытым окном)
- '%WINDIR%\syswow64\net.exe' start ServiceHelp
- '%WINDIR%\syswow64\net1.exe' start ServiceHelp
- '%WINDIR%\syswow64\svchost.exe' -k ServiceGroupEx
- '%WINDIR%\syswow64\cmd.exe' /c del %WINDIR%\SvcDate.exe