Техническая информация
- [HKLM\System\CurrentControlSet\Services\RemoteDesktop] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\RemoteDesktop] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [HKLM\SYSTEM\ControlSet001\Services\RemoteDesktop] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [HKLM\SYSTEM\ControlSet001\Services\RemoteDesktop\Parameters] 'ServiceDll' = '%ProgramFiles%\WinComms\UPFiles\realrm.dll'
- 'RemoteDesktop' <SYSTEM32>\svchost.exe -k netsvcs
- %WINDIR%\syswow64\bktype.txt
- %ProgramFiles%\wincomms\upfiles\realrm.dll
- %ProgramFiles%\wincomms\upfiles\kmain.exe
- %WINDIR%\syswow64\kmain.exe
- %WINDIR%\syswow64\clistr.wlh
- %WINDIR%\syswow64\bksetup.txt
- DNS ASK ip##8.com
- DNS ASK ds#.#eidog.net
- ClassName: 'MS_WINHELP' WindowName: ''