Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\EventSystemRoot] 'ImagePath' = '<SYSTEM32>\svchost.exe -k imgsvc'
- [<HKLM>\SYSTEM\ControlSet001\Services\EventSystemRoot] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- '<SYSTEM32>\svchost.exe' -k imgsvc
- '<SYSTEM32>\rundll32.exe' "%WINDIR%\Win1503900.ocx",CaoniM
- ClassName: 'pediy06' WindowName: ''
- ClassName: 'GBDYLLO' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- %ProgramFiles%\Google\Google v8.html
- C:\skin.jpg
- %WINDIR%\Win1503900.ocx
- C:\WinTemp.ini
- %ProgramFiles%\Google\Google v8.html
- %ProgramFiles%\Google\Google v8.html
- C:\WinTemp.ini
- C:\WinTemp.ini
- 'fm###2.gicp.net':3311
- 'fm####.linkpc.net':3313
- DNS ASK fm###2.gicp.net
- DNS ASK fm####.linkpc.net