Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\vmicshutdowns] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\vmicshutdowns] 'ImagePath' = '%WINDIR%\Fonts\a\svchost.exe'
- 'vmicshutdowns' %WINDIR%\Fonts\a\svchost.exe
- %WINDIR%\fonts\a\svchost.exe
- 'sh###.poolbt.com':20313
- 'bt#.#oolbt.com':5317
- 'bt#.#oolbt.com':20313
- DNS ASK sh###.poolbt.com
- DNS ASK bt#.#oolbt.com
- DNS ASK r.###gyou.com
- '%WINDIR%\fonts\a\svchost.exe'
- '%WINDIR%\fonts\a\svchost.exe' ' (со скрытым окном)