Техническая информация
- [HKLM\System\CurrentControlSet\Services\ConfigServices] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\ConfigServices] 'ImagePath' = '%ALLUSERSPROFILE%\ConfigServices\sysdircfg.exe'
- 'ConfigServices' %ALLUSERSPROFILE%\ConfigServices\sysdircfg.exe
- <SYSTEM32>\dwm.exe
- %ALLUSERSPROFILE%\configservices\sysdircfg.exe
- %WINDIR%\temp\zmoacfwdmskk.sys
- '18#.#56.72.39':5151
- '34.##9.100.209':443
- '%ALLUSERSPROFILE%\configservices\sysdircfg.exe'
- '<SYSTEM32>\sc.exe' delete "ConfigServices"
- '<SYSTEM32>\sc.exe' create "ConfigServices" binpath= "%ALLUSERSPROFILE%\ConfigServices\sysdircfg.exe" start= "auto"
- '<SYSTEM32>\sc.exe' start "ConfigServices"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\dwm.exe'