Техническая информация
- [HKLM\System\CurrentControlSet\Services\svchost32] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\svchost32] 'ImagePath' = '<SYSTEM32>\Setup\svchost.exe /service'
- [HKLM\System\CurrentControlSet\Services\Browser] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\PolicyAgent] 'Start' = '00000002'
- 'svchost32' <SYSTEM32>\Setup\svchost.exe /service
- Межсетевой экран (Брандмауэр Windows)
- Системный антивирус (Защитник Windows)
- %WINDIR%\syswow64\setup\svchost.exe
- DNS ASK ad###l-3.net
- 'localhost':50941
- 'localhost':63980
- '%WINDIR%\syswow64\setup\svchost.exe' /service
- '<SYSTEM32>\rundll32.exe' bfe.dll,BfeOnServiceStartTypeChange