Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\PROConnectSV] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\PROConnectSV] 'ImagePath' = '"%ALLUSERSPROFILE%\PRO32 Connect\wnoaqugmymczgegkruyrkexjeekdtcth-elevate.exe" -elevate \\.\pipe\elevateGS512wnoaqugmymczgeg...
- 'PROConnectSV' %ALLUSERSPROFILE%\PRO32 Connect\wnoaqugmymczgegkruyrkexjeekdtcth-elevate.exe" -elevate \.\pipe\elevateGS512wnoaqugmymczgegkruyrkexjeekdtct
- %ALLUSERSPROFILE%\pro32 connect\logs\20260612.log
- %ALLUSERSPROFILE%\pro32 connect\settings.dat
- %LOCALAPPDATA%\pro32 connect\settings.dat
- %ALLUSERSPROFILE%\pro32 connect\wnoaqugmymczgegkruyrkexjeekdtcth-elevate.exe
- %ALLUSERSPROFILE%\pro32 connect\memory\0000pipe0pcommand96pro32^connectovklstvhui83fmm
- %ALLUSERSPROFILE%\pro32 connect\logs\20260612.gui.log
- %ALLUSERSPROFILE%\pro32 connect\logs\20260612.capture.log
- %ALLUSERSPROFILE%\pro32 connect\wnoaqugmymczgegkruyrkexjeekdtcth-elevate.exe
- DNS ASK pr###connect.ru
- ClassName: 'GetscreenMeClassPRO32^Connect' WindowName: ''
- '%ALLUSERSPROFILE%\pro32 connect\wnoaqugmymczgegkruyrkexjeekdtcth-elevate.exe' -elevate \\.\pipe\elevateGS512wnoaqugmymczgegkruyrkexjeekdtcth