Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHelp32] 'Start' = '00000002'
- '%PROGRAM_FILES%\Internet Explorer\WinHelp32.exe'
- '%TEMP%\sg_test_10.exe'
- '%TEMP%\1.exe'
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://20#.##.108.37:8088/10.html
- NtTerminateProcess, драйвер-обработчик: DOWIRE.sys
- NtQuerySystemInformation, драйвер-обработчик: DOWIRE.sys
- %TEMP%\sg_test_10.exe
- <SYSTEM32>\r.dat
- <SYSTEM32>\DOWIRE.sys
- %PROGRAM_FILES%\Internet Explorer\WinHelp32.exe
- %TEMP%\1.exe
- %TEMP%\sg_test_10.exe
- %PROGRAM_FILES%\Internet Explorer\WinHelp32.exe
- %TEMP%\1.exe
- '59.##.68.170':8080
- '20#.#5.108.37':8088
- 'localhost':1037
- DNS ASK vv.##zhikan.com
- 'vv.##zhikan.com':37211
- 'localhost':1035
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'