Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsHost' = '%APPDATA%\WinHost\svchost.exe'
- %APPDATA%\WinHost\svchost.exe
- <SYSTEM32>\svchost.exe
- %WINDIR%\Explorer.EXE
- %APPDATA%\WinHost\svchost.exe
- 'de####esuncomp.at':80
- 'st####greenlj.com':80
- 'hi####entirion.su':80
- de####esuncomp.at/google/script.php
- st####greenlj.com/google/script.php
- hi####entirion.su/google/script.php
- DNS ASK de####esuncomp.at
- DNS ASK st####greenlj.com
- DNS ASK hi####entirion.su
- ClassName: 'Indicator' WindowName: ''