Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%APPDATA%\mssecurity\svchost.exe'
- [\REGISTRY\USER\S-1-5-21-3691498038-2086406363-2140527554-1000\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Security Essential' = '%APPDATA%\mssecurity\svchost.exe'
- [\REGISTRY\USER\S-1-5-21-3691498038-2086406363-2140527554-1000\Software\Microsoft\Windows\CurrentVersion\Run] 'systemupdate' = '<SYSTEM32>\update\system.exe'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'UserInit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\update\system.exe'
- %WINDIR%\syswow64\update\system.exe
- iexplore.exe
- 123.exe
- <Текущая директория>\123.exe
- %APPDATA%\mssecurity\svchost.exe
- %WINDIR%\syswow64\update\system.exe
- DNS ASK up#####ystem.no-ip.biz
- ClassName: 'EDIT' WindowName: ''
- '<Текущая директория>\123.exe'
- '%WINDIR%\syswow64\update\system.exe'