Техническая информация
- [<HKLM>\SYSTEM\CurrentControlSet\Services\242200bbd26f400fb4bf2b00bbf64dbf] 'ImagePath' = '%TEMP%\242200bbd26f400fb4bf2b00bbf64dbf\242200bbd26f400fb4bf2b00bbf64dbf.sys'
- [<HKLM>\System\CurrentControlSet\Services\{45487F67-EC9F-4449-A6F2-2D0970F9B80B}] 'Start' = '00000000'
- [<HKLM>\System\CurrentControlSet\Services\{45487F67-EC9F-4449-A6F2-2D0970F9B80B}] 'ImagePath' = 'system32\drivers\Wdf53691.sys'
- '242200bbd26f400fb4bf2b00bbf64dbf' %TEMP%\242200bbd26f400fb4bf2b00bbf64dbf\242200bbd26f400fb4bf2b00bbf64dbf.sys
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %TEMP%\242200bbd26f400fb4bf2b00bbf64dbf\242200bbd26f400fb4bf2b00bbf64dbf.sys
- <SYSTEM32>\config\000000
- <SYSTEM32>\config\000000.log1
- 's2.##tocz.com':80
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://x5.##tocz.com/data/drivers_updata/evan/vip/vip64
- http://s1.##tocz.com/p3ozm46rqzi54g4g04azms0
- http://s1.##tocz.com/05zzt803bzo2wz031jez7m3
- http://s1.##tocz.com/z3e18g908i9n8cr9605pc0zt
- http://s1.##tocz.com/7a2
- http://s1.##tocz.com/zdh0es05zt131n
- DNS ASK ip###ger.org
- DNS ASK microsoft.com
- DNS ASK s1.##tocz.com
- DNS ASK x5.##tocz.com
- DNS ASK s2.##tocz.com