Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'WinNetstat free 19091' = '<SYSTEM32>\natstats19091.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinNetstat free 19091' = '<SYSTEM32>\natstats19091.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinNetstat free 19091' = '<SYSTEM32>\natstats19091.exe'
- <SYSTEM32>\taskkill.exe /F /IM regedit.exe
- <SYSTEM32>\reg.exe add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa /f /v "WinNetstat free 19091" /d "<SYSTEM32>\natstats19091.exe"
- <SYSTEM32>\taskkill.exe /F /IM taskmgr.exe
- <SYSTEM32>\taskkill.exe /F /IM netstat.exe
- <SYSTEM32>\reg.exe add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /f /v "WinNetstat free 19091" /d "<SYSTEM32>\natstats19091.exe"
- <SYSTEM32>\reg.exe add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v "WinNetstat free 19091" /d "<SYSTEM32>\natstats19091.exe"
- <SYSTEM32>\reg.exe add HKEY_LOCAL_MACHINE\Software\Microsoft\OLE /f /v "WinNetstat free 19091" /d "<SYSTEM32>\natstats19091.exe"
- <SYSTEM32>\reg.exe add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices /f /v "WinNetstat free 19091" /d "<SYSTEM32>\natstats19091.exe"
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\natstats19091.exe
- 'la#####n97.sytes.net':6667
- '74.##5.232.51':80
- DNS ASK la#####n97.sytes.net
- DNS ASK www.google.com
- ClassName: '' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: '110515/2772'