Техническая информация
- [HKLM\System\CurrentControlSet\Services\oselocal] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\oselocal] 'ImagePath' = '<SYSTEM32>\oselocal.dll -Service'
- 'oselocal' <SYSTEM32>\oselocal.dll -Service
- C:\install-20100810-115254.exe
- C:\´úêõ»õ¿îóê¼þ»·½úðåöîö±Гóð½»¼äîþêõ¼ä.xls
- %WINDIR%\ena08e7dba3.tmp
- %WINDIR%\syswow64\oselocal.dll.tmp
- %WINDIR%\syswow64\oselocal.dll.dat
- %WINDIR%\syswow64\oselocal.dll.dat.txt
- %WINDIR%\syswow64\log\base.2024-10-09.log
- %WINDIR%\syswow64\df_tool.exe
- %WINDIR%\ena08e7dba3.tmp
- C:\install-20100810-115254.exe
- %WINDIR%\syswow64\oselocal.dll.tmp в %WINDIR%\syswow64\oselocal.dll
- 'localhost':135
- 'localhost':49156
- 'localhost':135
- 'localhost':49179
- 'localhost':49156
- 'localhost':49180
- DNS ASK qj##.#hagua911.cn
- 'C:\install-20100810-115254.exe'
- '%WINDIR%\syswow64\oselocal.dll' -Service
- '%WINDIR%\syswow64\df_tool.exe' C:\Install-20100810-115254.exe
- '%ProgramFiles%\microsoft office\office14\excel.exe' /dde
- '%WINDIR%\syswow64\df_tool.exe' C:\Install-20100810-115254.exe (со скрытым окном)