Техническая информация
- [HKLM\System\CurrentControlSet\Services\hnwflskys] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\hnwflskys] 'ImagePath' = '<SYSTEM32>\service.exe hnwflskys'
- 'hnwflskys' <SYSTEM32>\service.exe hnwflskys
- %WINDIR%\syswow64\service.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\wostmp\_231996161_1156298603
- '1.###.248.27':27930
- '17#.#6.12.203':27930
- '17#.#6.48.221':27930
- '17#.16.8.40':27930
- '<LOCALNET>.62.7':27930
- '<LOCALNET>.62.6':27930
- '17#.16.8.50':27930
- '10#.#16.52.20':27930
- '10#.#1.194.192':16800
- '<LOCALNET>.62.4':27930
- '<LOCALNET>.62.3':27930
- '<LOCALNET>.62.2':27930
- '14.#92.2.37':27930
- '<LOCALNET>.62.1':27930
- '<LOCALNET>.62.0':27930
- '<LOCALNET>.62.5':27930
- '11#.#10.212.150':27930
- '%WINDIR%\syswow64\service.exe' hnwflskys