Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\GoogleService.exe'
- '%WINDIR%\GoogleService.exe'
- %WINDIR%\Explorer.EXE
- %TEMP%\290593_res.tmp
- C:\MyTemp
- %WINDIR%\GoogleService.exe
- <SYSTEM32>\msoffice_ex.dll
- C:\MyTemp
- %TEMP%\290593_res.tmp в <SYSTEM32>\msoffice_ex.dll
- 'bl###.asis0day.biz':99
- 'bl###.asis0day.biz':8888
- DNS ASK Bl###.Asis0day.Biz