Техническая информация
- <SYSTEM32>\tasks\e6884678-1a6c-49d6-adcf-00f09782cfc8
- [HKLM\System\CurrentControlSet\Services\a84a7866-eb6b-4b1b-a4ac-1a241bea82cb] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\a84a7866-eb6b-4b1b-a4ac-1a241bea82cb] 'ImagePath' = '<SYSTEM32>\svchost.exe -k NetworkService'
- 'a84a7866-eb6b-4b1b-a4ac-1a241bea82cb' <SYSTEM32>\svchost.exe -k NetworkService
- <SYSTEM32>\svchost.exe
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\e6884678-1a6c-49d6-adcf-00f09782cfc8\e6884678-1a6c-49d6-adcf-00f09782cfc8.dll
- '31.##2.80.212':7002
- '31.##2.80.212':7001
- http://31.###.80.212:7002/simpledownload/apies via 31.##2.80.212
- http://31.###.80.212:7002/simpledownload/loader.bin via 31.##2.80.212
- '31.##2.80.212':7001
- '<SYSTEM32>\svchost.exe'