Техническая информация
- %WINDIR%\Tasks\MsUpdateTask.job
- [<HKLM>\SYSTEM\ControlSet001\Services\reggi] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\fanii] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\Schedule] 'Start' = '00000002'
- <SYSTEM32>\rundll32.exe /s "%WINDIR%\msnsi4.dll",SendStatisticDataOnInstall
- <SYSTEM32>\rundll32.exe %WINDIR%\msnsi4.dll,fnOpen
- <SYSTEM32>\rundll32.exe "%TEMP%\nsi3.tmp\BackOperHelper.dll",CloseExistedDllByRundll32 %WINDIR%\msnsi4.dll
- <SYSTEM32>\rundll32.exe /s "%WINDIR%\msnsi4.dll",UpdateIFEOInfo
- NtSetValueKey, драйвер-обработчик: reggi.sys
- NtDeleteValueKey, драйвер-обработчик: reggi.sys
- NtDeleteKey, драйвер-обработчик: reggi.sys
- %WINDIR%\msnsi4.dll
- %WINDIR%\reggi.sys
- <DRIVERS>\reggi.sys
- <DRIVERS>\fanii.sys
- %TEMP%\nsm2.tmp
- <SYSTEM32>\wbem\Performance\WmiApRpl_new.ini
- %WINDIR%\fanii.sys
- %TEMP%\nsi3.tmp\BackOperHelper.dll
- %TEMP%\nsi3.tmp\BackOperHelper.dll
- 'to##.kaola.cn':80
- to##.kaola.cn/toolPage/toolSn.jsp
- DNS ASK to##.kaola.cn
- ClassName: 'Shell_TrayWnd' WindowName: ''