Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Event Logs] 'Start' = '00000002'
- <SYSTEM32>\calc.exe
- C:\Event Logs.exe
- %PROGRAM_FILES%\EEvent Logs.exe
- C:\AutoRun.inf
- %WINDIR%\2010.txt
- %WINDIR%\Event Logs.exe
- C:\Event Logs.exe
- %PROGRAM_FILES%\EEvent Logs.exe
- %WINDIR%\Event Logs.exe
- C:\AutoRun.inf
- %WINDIR%\2010.txt
- 'ip.##079.net':80
- ip.##079.net/ip.txt
- DNS ASK ip.##079.net
- '<IP-адрес в локальной сети>':1035
- ClassName: 'TSxmanage' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'TAppBuilder' WindowName: ''