Техническая информация
- <SYSTEM32>\tasks\microsoft\windows\pla\system\smbdiag
- <SYSTEM32>\tasks\microsoft\windows\user profile service\slmgr32
- <SYSTEM32>\tasks\microsoft\windows\diagnosis\drivers\usbstor
- <SYSTEM32>\grouppolicy\machine\scripts\startup\smbdiag.vbe
- <SYSTEM32>\slmgr32.vbe
- <DRIVERS>\usbstor.vbe
- unc\fecysarzfeep*\mailslot\net\netlogon
- <SYSTEM32>\grouppolicy\machine\scripts\startup\smbdiag.vbe
- <SYSTEM32>\slmgr32.vbe
- <DRIVERS>\usbstor.vbe
- 'v4.#dent.me':80
- 'ap#.2ip.me':443
- http://v4.#dent.me/
- 'ap#.2ip.me':443
- DNS ASK v4.#dent.me
- DNS ASK v6.#dent.me
- DNS ASK ap#.2ip.me
- '<SYSTEM32>\wscript.exe' "<SYSTEM32>\grouppolicy\machine\scripts\startup\smbdiag.vbe"
- '<SYSTEM32>\wscript.exe' "<SYSTEM32>\grouppolicy\machine\scripts\startup\smbdiag.vbe" (со скрытым окном)