Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcjeQ9y.sys'
- [<HKLM>\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcxr2S5.sys'
- %TEMP%\~abcjeQ9y.sys
- %TEMP%\10vnxtl16p8.exe
- %TEMP%\~abcxr2S5.sys
- %APPDATA%\microsoft\internet explorer\userdata\index.dat
- %APPDATA%\microsoft\internet explorer\userdata\gpbnyoeo\userdatabidupsid[1].xml
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012019110320191104\index.dat
- %TEMP%\~abcjeQ9y.sys
- %TEMP%\~abcxr2S5.sys
- %TEMP%\~abcjeQ9y.sys
- %TEMP%\~abcxr2S5.sys
- http://do#####d.kulove123.com/tckz.txt
- http://do#####d.kulove123.com/QQgg.txt
- http://do#####d.kulove123.com/jxexe.txt
- DNS ASK do#####d.kulove123.com
- DNS ASK ba##u.com
- DNS ASK m.##idu.com
- DNS ASK ss#.##static.com
- DNS ASK sp#.#aidu.com
- ClassName: '' WindowName: 'Microsoft Internet Explorer'
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\10vnxtl16p8.exe'