Техническая информация
- [HKLM\System\CurrentControlSet\Services\Rsadon zatbghde] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rsadon zatbghde] 'ImagePath' = '<SYSTEM32>\Sgweowq.exe'
- 'Rsadon zatbghde' <SYSTEM32>\Sgweowq.exe
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %WINDIR%\syswow64\sgweowq.exe
- %WINDIR%\syswow64\sgweowq.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\1351577.bak
- '23.##4.102.149':1234
- '23.##4.102.149':1234
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\syswow64\sgweowq.exe'
- '%WINDIR%\syswow64\sgweowq.exe' Win7