Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run] '3U1RQL4X7GQLV' = '%APPDATA%\ZBHOHO25J.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run] '3U1RQL4X7GQLV' = '%APPDATA%\ZBHOHO25J.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '3U1RQL4X7GQLV' = '%APPDATA%\ZBHOHO25J.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'System Driver Component' = '"<SYSTEM32>\drvhost.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '3U1RQL4X7GQLV' = '%APPDATA%\ZBHOHO25J.exe'
- %ALLUSERSPROFILE%\Application Data\syshost.exe
- <SYSTEM32>\drvhost.exe
- %TEMP%\zbhoho25j.exe.jpg
- <SYSTEM32>\drvhost.exe
- %ALLUSERSPROFILE%\Application Data\syshost.exe
- <SYSTEM32>\drvhost.exe
- %ALLUSERSPROFILE%\Application Data\syshost.exe в %APPDATA%\ZBHOHO25J.exe
- '12###4345.net':80
- 12###4345.net/wc/alive.php?ke######################################################################################
- DNS ASK 12###4345.net
- ClassName: 'Indicator' WindowName: ''