Техническая информация
- [<HKLM>\SYSTEM\ControlSet002\Services\gowfwxr] 'ImagePath' = '<DRIVERS>\gowfwxr.sys'
- [<HKLM>\SYSTEM\ControlSet002\Services\gowfwxr] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\gowfwxr] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\gowfwxr] 'ImagePath' = '<DRIVERS>\gowfwxr.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\services.exe' = '<SYSTEM32>\services.exe:*:Enabled:ENABLE'
- '<SYSTEM32>\netsh.exe' firewall set allowedprogram <SYSTEM32>\services.exe ENABLE
- ClassName: '____AVP.Root', WindowName: ''
- <DRIVERS>\gowfwxr.sys
- %WINDIR%\Temp\sys408.tmp
- %TEMP%\espF9CB.tmp
- <Полный путь к файлу>
- %TEMP%\espF9CB.tmp
- %WINDIR%\Temp\sys408.tmp
- <Полный путь к файлу> в %TEMP%\tmp5188.tmp
- '64##846.net':80
- http:///wp-login.php via 64##846.net
- DNS ASK 64##846.net