Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\winlogon] 'Start' = '00000002'
- '%WINDIR%\Microsoft\winlogon.exe'
- '%WINDIR%\Microsoft\winlogon.exe' /run
- '%WINDIR%\Microsoft\winlogon.exe' /install
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\sc.exe' delete winlogon
- '<SYSTEM32>\sc.exe' stop winlogon
- %WINDIR%\Microsoft\Client\settings.dat
- %WINDIR%\Microsoft\Client\taskhost.exe
- <Текущая директория>\LogRTSS.dat
- %WINDIR%\Microsoft\winlogon.exe
- %WINDIR%\Microsoft\winlogon.InstallState
- %WINDIR%\Microsoft\Client\taskhost.exe
- 'dl.#####oxusercontent.com':443
- 'do######-new.utorrent.com':80
- 'wp#d':80
- 'sp######t.api-digital.com':80
- do######-new.utorrent.com/endpoint/utorrent/os/windows/track/stable/
- wp#d/wpad.dat
- sp######t.api-digital.com/speedtest/upload.php
- DNS ASK dl.#####oxusercontent.com
- DNS ASK do######-new.utorrent.com
- DNS ASK wp#d
- DNS ASK sp######t.api-digital.com