Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'XXXXXX71995912' = '%WINDIR%\XXXXXX71995912\svchsot.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHelps32] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinsHelsp32] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHelp329] 'Start' = '00000002'
- %WINDIR%\Temp\aa.exe
- <SYSTEM32>\WinsHelps32.exe
- <SYSTEM32>\WinHelps32.exe
- <SYSTEM32>\WinHelp32.exe
- %WINDIR%\Temp\dd.exe
- %WINDIR%\Temp\cc.exe
- %WINDIR%\Temp\bb.exe
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\WinsHelps32.exe
- <SYSTEM32>\WinHelp32.exe
- <SYSTEM32>\WinHelps32.exe
- %WINDIR%\XXXXXX71995912\svchsot.exe
- %WINDIR%\Temp\bb.exe
- %WINDIR%\Temp\aa.exe
- %WINDIR%\Temp\dd.exe
- %WINDIR%\Temp\cc.exe
- <SYSTEM32>\WinHelps32.exe
- <SYSTEM32>\WinsHelps32.exe
- <SYSTEM32>\WinHelp32.exe
- %WINDIR%\Temp\aa.exe
- %WINDIR%\Temp\bb.exe
- %WINDIR%\Temp\cc.exe
- 'any':8888
- 'www.xi###ijia.com':7777
- 'any':7777
- 'any':9999
- 'www.18###our.com':8888
- 'www.81###966.com':7171
- 'www.wk##88.com':7171
- 'www.ak##139.com':9999
- 'www.sn##13.com':7171
- DNS ASK www.ak##139.com
- DNS ASK www.18###our.com
- DNS ASK www.xi###ijia.com
- DNS ASK www.wk##88.com
- DNS ASK www.81###966.com
- DNS ASK www.sn##13.com
- ClassName: '' WindowName: '??????????????'