Техническая информация
- %WINDIR%\syswow64\svchost2.exe
- [HKCU\Software\Google\Google Talk\Accounts]
- [HKCU\Software\Paltalk]
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: 'gdkWindowToplevel', WindowName: ''
- %TEMP%\services.exe
- %TEMP%\keygen.exe
- %WINDIR%\syswow64\svchost2.exe
- %APPDATA%\chrtmp
- %WINDIR%\syswow64\svchost2.exe
- DNS ASK in#####to.shacknet.nu
- '%TEMP%\services.exe'
- '%TEMP%\keygen.exe'
- '%WINDIR%\syswow64\svchost2.exe'
- '%WINDIR%\syswow64\cmd.exe' /c timeout 5 && del %WINDIR%\SysWOW64\svchost2.exe (со скрытым окном)
- '%WINDIR%\syswow64\timeout.exe' 5