Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Print Device Synchronization] 'Start' = '00000002'
- '%ALLUSERSPROFILE%\Application Data\conmin.exe'
- %ALLUSERSPROFILE%\Application Data\svchost.exe
- %ALLUSERSPROFILE%\Application Data\conmin.exe
- %ALLUSERSPROFILE%\Application Data\Irrlicht.dll
- %ALLUSERSPROFILE%\Application Data\svchost.exe
- %ALLUSERSPROFILE%\Application Data\conmin.exe
- %ALLUSERSPROFILE%\Application Data\Irrlicht.dll
- 'ch####onday78.com':2013
- DNS ASK ch####onday78.com
- ClassName: 'Shell_TrayWnd' WindowName: ''