Техническая информация
- [HKLM\System\CurrentControlSet\Services\FastUserSwitchingCompatibility] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\FastUserSwitchingCompatibility] 'ImagePath' = '<SYSTEM32>\SVCHoST.EXE -K NETSVcS'
- [HKLM\system\cURRENTcONTROLsET\sERVICES\FastUserSwitchingCompatibility\Parameters] 'ServiceDll' = '<SYSTEM32>\FastUserSwitchingCompatibilityupt.dll'
- 'FastUserSwitchingCompatibility' <SYSTEM32>\SVCHoST.EXE -K NETSVcS
- %TEMP%\ixp000.tmp\Г¼æ¬½â~1.exe
- %WINDIR%\temp\l.bat
- %WINDIR%\temp\l.vbs
- %WINDIR%\temp\2.exe
- %WINDIR%\temp\2.jpg
- %WINDIR%\temp\d1.exe
- %TEMP%\726605_default.bak
- %WINDIR%\syswow64\fastuserswitchingcompatibilityupt.dll
- %TEMP%\ixp000.tmp\Г¼æ¬½â~1.exe
- %TEMP%\726605_default.bak в %WINDIR%\syswow64\fastuserswitchingcompatibilityupt.dll
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK gl##.3322.org
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- '%TEMP%\ixp000.tmp\Г¼æ¬½â~1.exe'
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\temp\l.vbs"
- '%WINDIR%\temp\2.exe'
- '%WINDIR%\temp\d1.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\Temp\l.bat" " (со скрытым окном)
- '%TEMP%\ixp000.tmp\Г¼æ¬½â~1.exe' (со скрытым окном)