Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\System] 'ImagePath' = '<SYSTEM32>\nssm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\System] 'Start' = '00000002'
- '<SYSTEM32>\nssm.exe' start System
- '<SYSTEM32>\nssm.exe'
- '<SYSTEM32>\driver.exe'
- '<SYSTEM32>\cmd.exe' /c "<SYSTEM32>\nssm.exe install System <SYSTEM32>\driver.exe > NUL && <SYSTEM32>\nssm.exe start System > NUL"
- '<SYSTEM32>\messg.exe'
- '<SYSTEM32>\nssm.exe' install System <SYSTEM32>\driver.exe
- <SYSTEM32>\nssm.exe
- <SYSTEM32>\driver.exe
- <SYSTEM32>\messg.exe
- 'ir#.#cene.org':6667
- DNS ASK ir#.#cene.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''