Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SystemGhost' = 'C:\Driver1\svcchost.exe'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- C:\Driver1\svcchost.exe
- 'sm##.gmail.com':465
- DNS ASK sm##.gmail.com
- ClassName: 'Indicator' WindowName: ''