Техническая информация
- [HKLM\System\CurrentControlSet\Services\Workstations] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Workstations] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [HKLM\SYSTEM\CurrentControlSet\Services\Workstations\Parameters] 'ServiceDll' = '%WINDIR%\SysWOW64\isvc.dll'
- 'Workstations' <SYSTEM32>\svchost.exe -k netsvcs
- %TEMP%\wi1196434nd.temp
- %TEMP%\tmpdwn.exe
- %TEMP%\wi1196434nd.temp в %WINDIR%\syswow64\isvc.dll
- '21#.#7.201.26':80
- http://21#.#7.201.26/info.txt
- '%WINDIR%\syswow64\rundll32.exe' isvc.dll RemoveService' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' isvc.dll InstallService' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' isvc.dll RemoveService
- '%WINDIR%\syswow64\rundll32.exe' isvc.dll InstallService