Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Winlogon_microsoft' = 'C:\ProgramData\programm\winlogon.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'microsoft_service' = 'C:\ProgramData\Bios\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows_host' = 'C:\ProgramData\Bios\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'microsoft_sustem' = 'C:\ProgramData\systems\drivers\system.exe'
- 'C:\ProgramData\Bios\svchost.exe'
- '<SYSTEM32>\wscript.exe' "<Current directory>\f.vbs"
- '<SYSTEM32>\ping.exe' www.ru
- C:\ProgramData\programm\winlogon.exe
- <Current directory>\f.vbs
- C:\ProgramData\Bios\svchost.exe
- C:\ProgramData\systems\drivers\system.exe
- C:\ProgramData\programm\winlogon.exe
- <Current directory>\f.vbs
- C:\ProgramData\Bios\svchost.exe
- C:\ProgramData\systems\drivers\system.exe
- 'ff####0008.url.ph':80
- 'localhost':1038
- DNS ASK ff####0008.url.ph
- DNS ASK www.ru
- ClassName: 'Indicator' WindowName: '(null)'