Техническая информация
- [HKLM\System\CurrentControlSet\Services\Tracing Client] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Tracing Client] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [HKLM\SYSTEM\CurrentControlSet\Services\Tracing Client\Parameters] 'ServiceDll' = '<SYSTEM32>\Tracng Client.dll'
- 'Tracing Client' <SYSTEM32>\svchost.exe -k netsvcs
- %TEMP%\9ba2.tmp
- %WINDIR%\syswow64\tracng client.dll
- DNS ASK gy####se.meibu.com
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\9BA2.tmp" "8A' 'U" (со скрытым окном)