Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\vVLWXt7z4W] 'ImagePath' = '<DRIVERS>\vVLWXt7z4W.sys'
- <SYSTEM32>\libeay32.dll
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\\8YeHbC.bat""
- '<SYSTEM32>\ping.exe' -n 2 127.1
- '<Текущая директория>\NetDncc.exe'
- '%ALLUSERSPROFILE%\hjgb13lY.exe' %ALLUSERSPROFILE%\ysqO_Csk.dll
- %WINDIR%\Explorer.EXE
- NtQuerySystemInformation, драйвер-обработчик: vVLWXt7z4W.sys
- %ALLUSERSPROFILE%\ysqO_Csk.dll
- %ALLUSERSPROFILE%\hjgb13lY.exe
- %TEMP%\8YeHbC.bat
- <Текущая директория>\NetDncc.exe
- <SYSTEM32>\blib.log
- <DRIVERS>\vVLWXt7z4W.sys
- <DRIVERS>\vVLWXt7z4W.sys
- %ALLUSERSPROFILE%\hjgb13lY.exe
- 'localhost':1039
- DNS ASK ip####ess.wb916.com
- DNS ASK www.qq.com
- DNS ASK c.##reg.com
- DNS ASK s.###ec.com.cn
- 's.###ec.com.cn':5049