Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Explorer' = '%CommonProgramFiles%\Microsoft Shared\services.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\winlogon.exe
- '%CommonProgramFiles%\Microsoft Shared\tuziA_v_AuTo.dll'
- '%CommonProgramFiles%\Microsoft Shared\services.exe'
- '<SYSTEM32>\reg.exe' ADD "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v Explorer /t REG_SZ /d "%CommonProgramFiles%\Microsoft Shared\services.exe"
- '<SYSTEM32>\cmd.exe' /c mybat.bat
- ClassName: 'OLLYDBG' WindowName: '(null)'
- ClassName: 'FileMonClass' WindowName: '(null)'
- %CommonProgramFiles%\Microsoft Shared\tuziA_v_AuTo.dll
- <Текущая директория>\mybat.bat
- %CommonProgramFiles%\Microsoft Shared\tuziA_v_AuTo.ocx
- %CommonProgramFiles%\Microsoft Shared\tuziA_v_Dw.ocx
- %CommonProgramFiles%\Microsoft Shared\services.exe
- %CommonProgramFiles%\Microsoft Shared\tuziA_v_AuTo.dll
- %CommonProgramFiles%\Microsoft Shared\services.exe
- %CommonProgramFiles%\Microsoft Shared\tuziA_v_AuTo.ocx
- %CommonProgramFiles%\Microsoft Shared\tuziA_v_Dw.ocx
- 'se###r.fx9t.com':111
- DNS ASK se###r.fx9t.com
- ClassName: '18467-41' WindowName: '(null)'