Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Dumper Host' = 'rundll32.exe "%TEMP%\winbdm.dll", RepCmd'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = '<SYSTEM32>\winphost.dll'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'LoadAppInit_DLLs' = '00000001'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'CTF Products Updater' = 'rundll32.exe "%TEMP%\winbdm.dll", RepCmd'
- Библиотека-обработчик для всех процессов: %TEMP%\winbdm.dll
- \KnownDlls
- \Registry\Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- %TEMP%\winbdm.dll
- %WINDIR%\syswow64\winphost.dll
- %TEMP%\_tpfc96.tmp
- %WINDIR%\syswow64\pcre3.dll
- %WINDIR%\syswow64\b_ctfmn.dll
- из <Полный путь к файлу> в %TEMP%\cac1075.tmp
- '<LOCALNET>.23.36':81
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\winbdm.dll", RepCmd