Техническая информация
- [HKLM\System\CurrentControlSet\Services\services32 utility manager] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\services32 utility manager] 'ImagePath' = '"%HOMEPATH%\svcchost32.exe"'
- 'services32 utility manager' "%HOMEPATH%\svcchost32.exe"
- 'services32 utility manager' %HOMEPATH%\svcchost32.exe
- %HOMEPATH%\svcchost32.exe
- %WINDIR%\syswow64\config\systemprofile\svcchost32.exe
- %HOMEPATH%\svcchost32.exe
- %WINDIR%\syswow64\config\systemprofile\svcchost32.exe
- 'ju#####egreat.0wtf.com':9111
- '34.##9.100.209':443
- DNS ASK ju#####egreat.0wtf.com
- ClassName: '#32770' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '%HOMEPATH%\svcchost32.exe'