Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\perfshl.exe] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\perfshl.exe] 'ImagePath' = '"%WINDIR%\SysWOW64\perfshl.exe" /s /p 27016'
- 'perfshl.exe' %WINDIR%\SysWOW64\perfshl.exe" /s /p 2701
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="perfshl.exe" dir=in action=allow program="%WINDIR%\SysWOW64\perfshl.exe" enable=yes profile=any
- %WINDIR%\syswow64\perfshl.exe
- 'gw#####he.bearshare.net':80
- http://gw#####he.bearshare.net/?ge############################################
- DNS ASK it####syouall.com
- DNS ASK gw#####he.bearshare.net
- DNS ASK gw#.##ufshop.com
- '23#.#55.255.250':1900
- '%WINDIR%\syswow64\perfshl.exe' /i
- '%WINDIR%\syswow64\perfshl.exe' /s /p 27016
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall delete rule name="perfshl.exe"