Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{JIP3WV6T-2MWM-U3XB-12FL-S138UO00SCM4}] 'StubPath' = 'C:\InstallDir\svchost.exe restart'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svchost' = 'C:\InstallDir\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'windows Defender' = 'C:\InstallDir\svchost.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- C:\InstallDir\svchost.exe
- %APPDATA%\Microsoft\Windows\aQX3Bb.cfg
- C:\InstallDir\svchost.exe
- %APPDATA%\Microsoft\Windows\aQX3Bb.cfg
- 'ho####.no-ip.org':88
- 'ho####.no-ip.org':89
- 'localhost':1037
- 'ho####.no-ip.org':87
- DNS ASK ho####.no-ip.org
- ClassName: 'Indicator' WindowName: ''