Техническая информация
- [HKLM\System\CurrentControlSet\Services\darkness] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\darkness] 'ImagePath' = '%WINDIR%\system\dwm.exe'
- 'darkness' %WINDIR%\system\dwm.exe
- [HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '\' = '%WINDIR%\system\dwm.exe:*:Enabled:KL'
- %WINDIR%\system\dwm.exe
- %WINDIR%\temp\ddid
- %WINDIR%\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
- 'be##job.in':80
- http://be##job.in/seo/index.php?ui####################
- DNS ASK be####j1o2b2.net
- DNS ASK be###job23.in
- DNS ASK be##job.in
- '%WINDIR%\system\dwm.exe' /start
- '%WINDIR%\system\dwm.exe'