Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\WindowsServiceHelper] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\WindowsServiceHelper] 'ImagePath' = '"%ProgramFiles%\WindowsServiceHelper\svc.exe"'
- 'WindowsServiceHelper' %ProgramFiles%\WindowsServiceHelper\svc.exe
- %TEMP%\7zipsfx.000\windowsservicechecker.vbs
- %TEMP%\7zipsfx.000\install.bat
- %TEMP%\7zipsfx.000\svc.xml
- %TEMP%\7zipsfx.000\svc.exe
- %ProgramFiles%\windowsservicehelper\svc.exe
- %ProgramFiles%\windowsservicehelper\svc.xml
- %ProgramFiles%\windowsservicehelper\windowsservicechecker.vbs
- %ProgramFiles%\windowsservicehelper\svc.wrapper.log
- %TEMP%\7zsfx000.cmd
- %WINDIR%\temp\content\1048-1172-cscript.exe-18-14-18-137.dump
- %ProgramFiles%\windowsservicehelper\id.txt
- %TEMP%\7zipsfx.000\install.bat
- %TEMP%\7zipsfx.000\svc.exe
- %TEMP%\7zipsfx.000\svc.xml
- %TEMP%\7zipsfx.000\windowsservicechecker.vbs
- '45.##0.109.2':80
- '%ProgramFiles%\windowsservicehelper\svc.exe' install
- '%ProgramFiles%\windowsservicehelper\svc.exe' start
- '%ProgramFiles%\windowsservicehelper\svc.exe'
- '<SYSTEM32>\cscript.exe' //Nologo //B "%ProgramFiles%\WindowsServiceHelper\WindowsServiceChecker.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZipSfx.000\install.bat" " (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" " (со скрытым окном)