Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SVKP] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SVKP] 'ImagePath' = '<SYSTEM32>\SVKP.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows workstatn] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows workstatn] 'ImagePath' = '%WINDIR%\svchost.exe'
- IEXPLORE.EXE
- <SYSTEM32>\SVKP.sys
- %WINDIR%\svchost.exe
- %WINDIR%\uninstal.bat
- %WINDIR%\svchost.exe
- <Полный путь к файлу>
- '23####117.vicp.net':80
- http://23####117.vicp.net/ip.txt
- DNS ASK 23####117.vicp.net
- '%WINDIR%\svchost.exe'
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\uninstal.bat