Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\servicesec] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\servicesec] 'ImagePath' = '%WINDIR%\SysWOW64\servicesec.exe'
- 'servicesec' %WINDIR%\SysWOW64\servicesec.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\servicesec.exe
- '13#.#01.226.235':443
- '91.##4.217.195':8080
- '10#.#4.149.195':8080
- http://13#.##1.226.235:443/ via 13#.#01.226.235