Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Syclover' = '%WINDIR%\Sample.vbs'
- [<HKCU>\Software\Classes\.syclover\shell\open\command] '' = '%WINDIR%\notepad.exe %1'
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '<Текущая директория>\WinRing0x64.sys'
- 'WinRing0_1_2_0' <Текущая директория>\WinRing0x64.sys
- %WINDIR%\img.exe
- %WINDIR%\sample.vbs
- <Текущая директория>\sample.bat
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK ra#.####ubusercontent.com
- DNS ASK microsoft.com
- DNS ASK xm######ast1.nanopool.org