Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'CSRSS' = '"%ALLUSERSPROFILE%\Drivers\csrss.exe"'
- %ALLUSERSPROFILE%\drivers\csrss.exe
- %TEMP%\4kpv6a~1\state.tmp
- %ALLUSERSPROFILE%\drivers\csrss.exe
- %TEMP%\4kpv6a~1\state.tmp в %TEMP%\4kpv6a~1\state
- 'localhost':49179
- '62.##6.54.29':9001
- '17#.#23.3.222':9001
- '87.#48.7.41':9003
- '87.##1.147.113':9001
- '15#.#5.175.225':443
- '88.#8.79.90':80