Техническая информация
- [HKLM\System\CurrentControlSet\Services\Svc_Systems] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Svc_Systems] 'ImagePath' = '"C:\sys\svchoct.exe" -service'
- 'Svc_Systems' "C:\sys\svchoct.exe" -service
- C:\sys\bin_.zip
- %TEMP%\vmsd8c1.tmp
- C:\sys\svchoct.exe
- %TEMP%\vmsd95e.tmp
- C:\sys\systemcache.exe
- C:\sys\svchoct.exe
- C:\sys\systemcache.exe
- %TEMP%\vmsd8c1.tmp
- %TEMP%\vmsd95e.tmp
- C:\sys\bin_.zip
- 'up####-service.org':80
- http://up####-service.org/config.txt
- http://up####-service.org/accounts.php
- DNS ASK up####-service.org
- 'C:\sys\svchoct.exe'
- 'C:\sys\svchoct.exe' -service
- 'C:\sys\systemcache.exe'