Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\userinit] 'ImagePath' = '\\.\globalroot<SYSTEM32>\usеrinit.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\userinit] 'Start' = '00000002'
- Центр обеспечения безопасности (Security Center)
- <SYSTEM32>\usеrinit.exe
- <SYSTEM32>\svchost.exe
- %WINDIR%\Explorer.EXE
- %TEMP%\{E9C1E0AC-C9B1-4c85-94DE-9C1518918D02}.tlb
- %TEMP%\{E9C1E0AC-C9B1-4c85-94DE-9C1518918D01}.tlb
- %ALLUSERSPROFILE%\Application Data\.wtav
- <SYSTEM32>\exefile.exe
- <SYSTEM32>\usеrinit.exe
- <SYSTEM32>\msbzsnor.dll
- 'localhost':1043
- '95.##1.21.181':8083
- DNS ASK
- '<IP-адрес в локальной сети>':1040
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'z00clicker' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''