Техническая информация
- [HKLM\System\CurrentControlSet\Services\RISING soft] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\RISING soft] 'ImagePath' = '<SYSTEM32>\aeouew.exe'
- 'RISING soft' <SYSTEM32>\aeouew.exe
- 'RISING soft' <SYSTEM32>\pgvdgk.exe
- %WINDIR%\syswow64\aeouew.exe
- %WINDIR%\syswow64\pgvdgk.exe
- 'localhost':8080
- '%WINDIR%\syswow64\aeouew.exe'