Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\srvPlgProtect] 'Start' = '00000002'
- '%APPDATA%\okitspace\protect\PluginProtect.exe'
- %APPDATA%\okitspace\protect\sqlite3.exe
- %APPDATA%\okitspace\protect\Newtonsoft.Json.dll
- %APPDATA%\okitspace\protect\utilsDll.dll
- %APPDATA%\okitspace\uninstallkit.exe
- %APPDATA%\okitspace\protect\config.xml
- %TEMP%\nsf2.tmp\registry.dll
- %TEMP%\nsf2.tmp\SimpleSC.dll
- %TEMP%\nsf2.tmp\utils.dll
- %APPDATA%\okitspace\protect\Interop.Shell32.dll
- %APPDATA%\okitspace\protect\PluginProtect.exe
- %TEMP%\nsf2.tmp\utils.dll
- %TEMP%\nsf2.tmp\SimpleSC.dll
- %TEMP%\nsf2.tmp\registry.dll
- 'st###.okitspace.com':443
- DNS ASK st###.okitspace.com