Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft WinService' = '<SYSTEM32>\winservices.exe'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\winservices.exe,'
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft WinService' = '<SYSTEM32>\winservices.exe'
- <SYSTEM32>\winservices.exe
- %APPDATA%\serviceloader.exe
- '34.##9.100.209':443
- DNS ASK h0##.secure.la
- DNS ASK se#.##secure.biz
- '<SYSTEM32>\winservices.exe' [install]
- '%APPDATA%\serviceloader.exe' [persistance{<SYSTEM32>\winservices.exe}]