Техническая информация
- [HKLM\System\CurrentControlSet\Services\flead] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\flead] 'ImagePath' = '<SYSTEM32>\Isass.exe daelf.dll,LocalSystem xbGloc2lsaW4uY24A'
- 'flead' <SYSTEM32>\Isass.exe daelf.dll,LocalSystem xbGloc2lsaW4uY24A
- %HOMEPATH%\setup.exe
- %WINDIR%\syswow64\daelf.dll
- %WINDIR%\syswow64\isass.exe
- %WINDIR%\syswow64\flead.exe
- %HOMEPATH%\setup.exe
- из <Полный путь к файлу> в \:x
- '34.##9.100.209':443
- DNS ASK li##ilin.cn
- '%HOMEPATH%\setup.exe'
- '%WINDIR%\syswow64\isass.exe' daelf.dll,LocalSystem xbGloc2lsaW4uY24A
- '%WINDIR%\syswow64\flead.exe' daelf.dll,LocalSystem xbGloc2lsaW4uY24A