Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\DBTHPR] 'ImagePath' = '%WINDIR%\DBTHPR.sys'
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- '<SYSTEM32>\cmd.exe' /c %TEMP%\\xxxxxx.bat
- <SYSTEM32>\winlogon.exe
- <SYSTEM32>\services.exe
- %WINDIR%\DBTHPR.sys
- %TEMP%\xxxxxx.bat
- %WINDIR%\DBTHSA.log
- %WINDIR%\DBTHSA.tmp
- %WINDIR%\DBTHSA.dll
- 'localhost':31400