Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\NtSSDPSRV] 'Start' = '00000002'
- <SYSTEM32>\cmd.exe /c %TEMP%\dvi.bat
- <SYSTEM32>\svchost.exe -k NtSSDPSRV
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'OllyDbg' WindowName: ''
- <SYSTEM32>\c_501.nls
- <SYSTEM32>\c_1125.nls
- <SYSTEM32>\c_640.nls
- %TEMP%\dvi.bat
- <SYSTEM32>\C_1183.NLS
- <SYSTEM32>\Bot_ProgSvcDll(Revise).dll_
- <SYSTEM32>\ntsjsvc.dll
- <SYSTEM32>\C_1183.NLS
- <SYSTEM32>\Bot_ProgSvcDll(Revise).dll_
- ClassName: 'WinDbgFrameClass' WindowName: ''
- ClassName: 'SandboxieControlWndClass' WindowName: ''
- ClassName: '18467-41' WindowName: ''