Техническая информация
- [HKLM\System\CurrentControlSet\Services\Rssuag funfjxzb] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Rssuag funfjxzb] 'ImagePath' = '%WINDIR%\Eswowg.exe -svc'
- 'Rssuag funfjxzb' %WINDIR%\Eswowg.exe -svc
- <SYSTEM32>\conhost.exe
- C:\kernel.txt
- C:\users\public\documents\netuser.tmp
- <SYSTEM32>\ini.ini
- %WINDIR%\eswowg.exe
- %WINDIR%\eswowg.exe
- '34.##9.100.209':443
- '34.##9.100.209':443
- '%WINDIR%\eswowg.exe' -svc