Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\Bcdefg] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Bcdefg] 'ImagePath' = '%WINDIR%\svchost.exe'
- 'Bcdefg' %WINDIR%\svchost.exe
- %WINDIR%\svchost.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\996031.bak
- '12#.#20.16.158':8080
- '12#.#20.16.158':8080
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- '%WINDIR%\svchost.exe'
- '%WINDIR%\svchost.exe' Win7