Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\TlntSvr] 'Start' = '00000002'
- <SYSTEM32>\tlntsvr.exe файлом <SYSTEM32>\tlntsvr.exe
- <SYSTEM32>\tlntsvr.exe
- ClassName: '#32770' WindowName: 'Windows File Protection'
- <SYSTEM32>\dllcache\tlntsvr.exe
- <SYSTEM32>\tlntsvr.exe в <SYSTEM32>\tlntsvr.exe.bak
- '2f###.#esimzade.com.cn':80
- '2d###.#anowark.com.cn':80
- 2d###.#anowark.com.cn/update/version.txt
- DNS ASK 2f###.#esimzade.com.cn
- DNS ASK 2d###.#anowark.com.cn
- ClassName: '#32770' WindowName: 'Windows ????????'