Техническая информация
- [HKLM\System\CurrentControlSet\Services\OleView] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\OleView] 'ImagePath' = '%ALLUSERSPROFILE%\OleView\OleView.exe'
- 'OleView' %ALLUSERSPROFILE%\OleView\OleView.exe
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\msiexec.exe
- %TEMP%\rarsfx0\oleview.exe
- %TEMP%\rarsfx0\aclui.dll
- %TEMP%\rarsfx0\aclui.dll.ui
- %ALLUSERSPROFILE%\oleview\aclui.dll
- %ALLUSERSPROFILE%\oleview\aclui.dll.ui
- %ALLUSERSPROFILE%\oleview\oleview.exe
- %ALLUSERSPROFILE%\sxs\bug.log
- %ALLUSERSPROFILE%\oleview\aclui.dll
- %ALLUSERSPROFILE%\oleview\aclui.dll.ui
- %ALLUSERSPROFILE%\oleview\oleview.exe
- %TEMP%\rarsfx0\aclui.dll
- %TEMP%\rarsfx0\aclui.dll.ui
- %TEMP%\rarsfx0\oleview.exe
- DNS ASK ft#.###acingmotor.com
- '<LOCALNET>.40.255':53
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\oleview.exe'
- '%ALLUSERSPROFILE%\oleview\oleview.exe'
- '%WINDIR%\syswow64\svchost.exe' 201 0
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\syswow64\wininet.DLL",DispatchAPICall 1
- '%WINDIR%\syswow64\msiexec.exe' 209 248