Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\420a0a1f] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\420a0a1f] 'ImagePath' = '<DRIVERS>\420a0a1f.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\neverdeath] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\neverdeath] 'ImagePath' = '<DRIVERS>\xpV3001.sys'
- <SYSTEM32>\ws2help.dll
- <SYSTEM32>\ws2help.dll
- '<SYSTEM32>\cmd.exe' /c del "<Полный путь к файлу>"
- '<SYSTEM32>\cmd.exe' /c del "%TEMP%\vJEHjZR.exe"
- '%TEMP%\vJEHjZR.exe'
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'FileMonClass', WindowName: ''
- <DRIVERS>\420a0a1f.sys
- <SYSTEM32>\ws2helpXP.dll
- %TEMP%\vJEHjZR.exe
- <DRIVERS>\xpV3001.sys
- %TEMP%\vJEHjZR.exe
- <SYSTEM32>\ws2help.dll в <SYSTEM32>\ws2help.dll.kvK.tmp
- ClassName: '18467-41' WindowName: ''