Техническая информация
- [HKLM\System\CurrentControlSet\Services\MicrosoftWNT] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\MicrosoftWNT] 'ImagePath' = '%ProgramFiles%\Windows NT\gamedump.exe'
- 'MicrosoftWNT' %ProgramFiles%\Windows NT\gamedump.exe
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\dllhost.exe
- %ProgramFiles%\windows nt\gamedump.exe
- %ProgramFiles%\windows nt\bh3base.dll
- %ProgramFiles%\windows nt\mimidump.inf
- '15#.#51.18.37':80
- '15#.#51.18.37':80
- '%ProgramFiles%\windows nt\gamedump.exe'
- '<SYSTEM32>\svchost.exe' -k netsvcs (со скрытым окном)