Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'jusched' = '%WINDIR%\igfxsrvc.exeSOFTWARE\Microsoft\Windows\CurrentVersion\run'
- '%WINDIR%\jusched.exe' (загружен из сети Интернет)
- '%WINDIR%\igfxsrvc.exe' (загружен из сети Интернет)
- '%WINDIR%\igfxsrvc.exe'
- '%WINDIR%\jusched.exe'
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\run /v jusched /t REG_SZ /d %WINDIR%\igfxsrvc.exeSOFTWARE\Microsoft\Windows\CurrentVersion\run
- '<SYSTEM32>\reg.exe' add HKLM\ /v jusched /t REG_SZ /d %WINDIR%\jusched.exe
- %WINDIR%\jusched.exe
- %WINDIR%\igfxsrvc.exe
- 'rk#######kaus.freehostia.com':80
- http://rk#######kaus.freehostia.com/log.php via rk#######kaus.freehostia.com
- http://rk#######kaus.freehostia.com/2 via rk#######kaus.freehostia.com
- http://rk#######kaus.freehostia.com/1 via rk#######kaus.freehostia.com
- DNS ASK rk#######kaus.freehostia.com