Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Хост-процесс для служб Windows' = '%WINDIR%\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Хост-процесс для служб Windows' = '%WINDIR%\svchost.exe'
- '%WINDIR%\svchost.exe'
- '%TEMP%\d2s2.exe' %TEMP%\d2s2.exe
- '%TEMP%\23r1.exe' %TEMP%\23r1.exe
- %WINDIR%\svchost.exe
- %TEMP%\d2s2.exe
- %TEMP%\23r1.exe
- %TEMP%\23r1.exe
- %TEMP%\d2s2.exe
- 'ar##.500mb.net':80
- 'wp#d':80
- 'ho######01.servebeer.com':25500
- ar##.500mb.net/Chat_ANTIAFK.html
- wp#d/wpad.dat
- DNS ASK ar##.500mb.net
- DNS ASK wp#d
- DNS ASK ho######01.servebeer.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'tooltips_class32' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''