Техническая информация
- [<HKLM>\software\Wow6432Node\microsoft\windows\CurrentVersion\Run] 'JRStartupItem' = 'C:\proxystart.vbs'
- [<HKLM>\System\CurrentControlSet\Services\Drivedail64x] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\Drivedail64x] 'ImagePath' = 'system32\drivers\Drivedail64x.sys'
- 'Drivedail64x' system32\drivers\Drivedail64x.sys
- C:\proxystart.vbs
- C:\lzsock.ini
- <Текущая директория>\lzgiant.dll
- %HOMEPATH%\documents\ws_sock.ini
- <DRIVERS>\drivedail64x.sys
- ctrlsmdrivedail64x
- C:\sock.ini
- %WINDIR%\temp\uddbfd5.tmp
- %WINDIR%\temp\uddbfd5.tmp