Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\PRO32ConnectSV] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\PRO32ConnectSV] 'ImagePath' = '"%ALLUSERSPROFILE%\PRO32 Connect\luxqrfdhwjhrhkglxykmbrmmosnobyz-elevate.exe" -elevate \\.\pipe\elevateGS512luxqrfdhwjhrhk...
- 'PRO32ConnectSV' %ALLUSERSPROFILE%\PRO32 Connect\luxqrfdhwjhrhkglxykmbrmmosnobyz-elevate.exe" -elevate \.\pipe\elevateGS512luxqrfdhwjhrhkglxykmbrmmosnoby
- %ALLUSERSPROFILE%\pro32 connect\settings.dat
- %LOCALAPPDATA%\pro32 connect\settings.dat
- %ALLUSERSPROFILE%\pro32 connect\logs\20260610.log
- %ALLUSERSPROFILE%\pro32 connect\luxqrfdhwjhrhkglxykmbrmmosnobyz-elevate.exe
- %ALLUSERSPROFILE%\pro32 connect\memory\0000pipe0pcommand96pro32^connect0
- %ALLUSERSPROFILE%\pro32 connect\luxqrfdhwjhrhkglxykmbrmmosnobyz-elevate.exe
- DNS ASK pr###connect.ru
- DNS ASK ms####nnecttest.com
- ClassName: 'GetscreenMeClassPRO32^Connect' WindowName: ''
- '%ALLUSERSPROFILE%\pro32 connect\luxqrfdhwjhrhkglxykmbrmmosnobyz-elevate.exe' -elevate \\.\pipe\elevateGS512luxqrfdhwjhrhkglxykmbrmmosnobyz