Техническая информация
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'skype' = '<SYSTEM32>\Windows\taskmgr.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'rede' = '<SYSTEM32>\Windows\taskmgr.exe'
- [HKLM\Software\WOW6432Node\Microsoft\Active Setup\Installed Components\{1G442AT7-7B0J-K63T-JL83-K34EG5M5G8IB}] 'StubPath' = '<SYSTEM32>\Windows\taskmgr.exe restart'
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\windows\taskmgr.exe
- %WINDIR%\syswow64\windows\taskmgr.exe
- DNS ASK ca#####xoro.no-ip.org
- DNS ASK fi#####.###tings.services.mozilla.com
- '%WINDIR%\syswow64\svchost.exe'