Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\hUoqrKurG] 'ImagePath' = '<DRIVERS>\hUoqrKurG.sys'
- 'hUoqrKurG' <DRIVERS>\hUoqrKurG.sys
- %WINDIR%\otalm.txt
- %WINDIR%\appcompat\8900.tmp
- %WINDIR%\system\8903.tmp
- %WINDIR%\system\wu02\c_20445.nls
- <DRIVERS>\huoqrkurg.sys
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cert9.db
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\key4.db
- %WINDIR%\tracing\5128.tmp
- %WINDIR%\tracing\wu04\c_10247.nls
- %WINDIR%\appcompat\8900.tmp
- %WINDIR%\system\8903.tmp
- <DRIVERS>\huoqrkurg.sys
- %WINDIR%\tracing\5128.tmp
- http://li##.##kuai8.com:6666/47f5beb28720d88ac09f9b2aab4c8573.txt via li##.#dkuai8.com
- http://47.##.198.191:6666/af386612a461f075a9f0e1320e7aa99d.exe
- http://47.##.220.198:7892/0a0027000007.txt via 47.##.220.198
- http://47.##.198.191:50527/bcf3a77c8d32416a1c8cc5673d50677b.zip
- http://47.##.198.191:50044/65e4e58b2476aa567098fdefb918e262.zip
- http://cn.bing.com/
- http://61.###.11.135:50777/b6a18154611e9a17502c6e47ef4881b4.zip via 61.##0.11.135
- DNS ASK g7#####Y.adkuai8.com
- DNS ASK li##.#dkuai8.com
- DNS ASK cn.bing.com
- '<LOCALNET>.7.255':18691
- '47.##.220.198':7890
- '47.##.220.198':8081
- '47.##.119.96':21785
- '255.255.255.255':29352
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<Полный путь к файлу>"