Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [<HKLM>\System\CurrentControlSet\Services\Process Manager Service] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Process Manager Service] 'ImagePath' = '%ProgramFiles%\Zombie ZERO\regsvc.exe'
- [<HKLM>\System\CurrentControlSet\Services\FileScan] 'ImagePath' = 'system32\DRIVERS\FileScan.sys'
- [<HKLM>\System\CurrentControlSet\Services\nptdimon] 'ImagePath' = 'System32\Drivers\nptdimon.sys'
- 'Process Manager Service' %ProgramFiles%\Zombie ZERO\regsvc.exe
- 'FileScan' system32\DRIVERS\FileScan.sys
- 'nptdimon' System32\Drivers\nptdimon.sys
- '<SYSTEM32>\net.exe' stop FileScan
- [<HKLM>\System\CurrentControlSet\Services\FileScan] 'Group' = 'FSFilter Anti-Virus'
- %TEMP%\nsm4f49.tmp\version.dll
- %ProgramFiles%\zombie zero\x86\mfc100u.dll
- %ProgramFiles%\zombie zero\x86\mfcm100.dll
- %ProgramFiles%\zombie zero\x86\mfcm100u.dll
- %ProgramFiles%\zombie zero\x86\msvcp100.dll
- %ProgramFiles%\zombie zero\x86\msvcr100.dll
- %ProgramFiles%\zombie zero\x86\scan.dll
- %ProgramFiles%\zombie zero\x86\trufos.dll
- %ProgramFiles%\zombie zero\avxdisk.dll
- %ProgramFiles%\zombie zero\bdardrv.dll
- %ProgramFiles%\zombie zero\bdarw.dll
- %ProgramFiles%\zombie zero\bdcore.dll
- %ProgramFiles%\zombie zero\bdquar.dll
- %ProgramFiles%\zombie zero\bdsmartdb.dll
- %ProgramFiles%\zombie zero\bdupdateservicecom.dll
- %ProgramFiles%\zombie zero\gzfltum.dll
- %ProgramFiles%\zombie zero\x86\mfc100.dll
- %ProgramFiles%\zombie zero\mfc100.dll
- %ProgramFiles%\zombie zero\x86\gzfltum.dll
- %ProgramFiles%\zombie zero\x86\bdquar.dll
- %ProgramFiles%\zombie zero\x64\mfc100.dll
- %ProgramFiles%\zombie zero\x64\mfc100u.dll
- %ProgramFiles%\zombie zero\x64\mfcm100.dll
- %ProgramFiles%\zombie zero\x64\mfcm100u.dll
- %ProgramFiles%\zombie zero\x64\msvcp100.dll
- %ProgramFiles%\zombie zero\x64\msvcr100.dll
- %ProgramFiles%\zombie zero\x64\scan.dll
- %ProgramFiles%\zombie zero\x64\trufos.dll
- %ProgramFiles%\zombie zero\x86\bcgcbpro2900u100.dll
- %ProgramFiles%\zombie zero\x86\bdupdateservicecom.dll
- %ProgramFiles%\zombie zero\x86\oemuninstall.dll
- %ProgramFiles%\zombie zero\x86\avxdisk.dll
- %ProgramFiles%\zombie zero\x86\bdardrv.dll
- %ProgramFiles%\zombie zero\x86\bdarw.dll
- %ProgramFiles%\zombie zero\x86\bdcore.dll
- %ProgramFiles%\zombie zero\x86\bdsmartdb.dll
- %ProgramFiles%\zombie zero\mfc100u.dll
- %ProgramFiles%\zombie zero\mfcm100.dll
- %ProgramFiles%\zombie zero\mfcm100u.dll
- %ProgramFiles%\zombie zero\log\20210719\regsvc_info.log
- %ProgramFiles%\zombie zero\log\20210719\regsvc_error.log
- <DRIVERS>\sete4a3.tmp
- %WINDIR%\temp\uddec13.tmp
- %ProgramFiles%\zombie zero\data\policydb.db-journal
- %ProgramFiles%\zombie zero\data\policydb.db
- %ProgramFiles%\zombie zero\log\20210719\zzero_info_2844.log
- %ProgramFiles%\zombie zero\data\requestdb.db-journal
- %ProgramFiles%\zombie zero\log\20210719\zzerosrvc_info.log
- %ProgramFiles%\zombie zero\data\zzerodb.db-journal
- %ProgramFiles%\zombie zero\data\zzerodb.db
- <DRIVERS>\nptdimon.sys
- %ProgramFiles%\zombie zero\log\20210719\zzerosrvc_error.log
- %WINDIR%\temp\udd313e.tmp
- %ProgramFiles%\zombie zero\language\1041\csrst_msg.ini
- %ProgramFiles%\zombie zero\language\1042\csrst_msg.ini
- %ProgramFiles%\zombie zero\language\1033\csrst_msg.ini
- %ALLUSERSPROFILE%\innotium\ncfootprint\csbackup\setfile.~cst\cstask1000.~cst
- %ALLUSERSPROFILE%\innotium\ncfootprint\csbackup\cssysinfo.~cst
- %ProgramFiles%\zombie zero\msvcp100.dll
- %ProgramFiles%\zombie zero\msvcr100.dll
- %ProgramFiles%\zombie zero\oemuninstall.dll
- %ProgramFiles%\zombie zero\scan.dll
- %ProgramFiles%\zombie zero\trufos.dll
- %ProgramFiles%\zombie zero\filescan.sys
- %ProgramFiles%\zombie zero\x64\gzfltum.dll
- %ProgramFiles%\zombie zero\filescan.cat
- %ProgramFiles%\zombie zero\filescan.inf
- %ProgramFiles%\zombie zero\nptdimon.inf
- %ProgramFiles%\zombie zero\nptdimon.cat
- %ProgramFiles%\zombie zero\imhdrv6.sys
- %ProgramFiles%\zombie zero\imhdrv6.cat
- %ProgramFiles%\zombie zero\imhdrv6.inf
- %ALLUSERSPROFILE%\innotium\ncfootprint\cssysinfo.~cst
- %ProgramFiles%\zombie zero\bcgcbpro2900u100.dll
- %ProgramFiles%\zombie zero\nptdimon.sys
- %ProgramFiles%\zombie zero\data\requestdb.db
- %ProgramFiles%\zombie zero\x64\bdsmartdb.dll
- %ProgramFiles%\zombie zero\drivers\xp\nptdimon.sys
- %ProgramFiles%\zombie zero\allowfiles.ini
- %ProgramFiles%\zombie zero\zzero.ico
- %ProgramFiles%\zombie zero\zzero2.ico
- %ProgramFiles%\zombie zero\zzero3.ico
- %ProgramFiles%\zombie zero\zzero4.ico
- %ProgramFiles%\zombie zero\7za.exe
- %ProgramFiles%\zombie zero\ssl.cer
- %ProgramFiles%\zombie zero\npcore.cer
- %ProgramFiles%\zombie zero\libeay32.dll
- %ProgramFiles%\zombie zero\libssh2.dll
- %ProgramFiles%\zombie zero\ncaccprvt.exe
- %ProgramFiles%\zombie zero\nccallflt_x64.sys
- %ProgramFiles%\zombie zero\nccallflt_x86.sys
- %ProgramFiles%\zombie zero\ncfooteng.exe
- %ProgramFiles%\zombie zero\ncfootprint.dll
- %ProgramFiles%\zombie zero\regsvc.ini
- %ProgramFiles%\zombie zero\ncfootprint_x64.dll
- %ProgramFiles%\zombie zero\resjpnx64.dll
- %ProgramFiles%\zombie zero\reskorx64.dll
- %TEMP%\nsm4f49.tmp\system.dll
- %TEMP%\nsm4f49.tmp\userinfo.dll
- %TEMP%\nsm4f49.tmp\nsexec.dll
- %TEMP%\nsm4f49.tmp\nsprocess.dll
- %ProgramFiles%\zombie zero\zzero.exe
- %ProgramFiles%\zombie zero\zzerox64.exe
- %ProgramFiles%\zombie zero\zzerosrvc.exe
- %ProgramFiles%\zombie zero\zzerosrvcx64.exe
- %ProgramFiles%\zombie zero\regsvc.exe
- %ProgramFiles%\zombie zero\regsvcx64.exe
- %ProgramFiles%\zombie zero\util.exe
- %ProgramFiles%\zombie zero\utilx64.exe
- %ProgramFiles%\zombie zero\wdfcoinstaller01009.dll
- %ProgramFiles%\zombie zero\wdfcoinstaller01009x64.dll
- %ProgramFiles%\zombie zero\reskor.dll
- %ProgramFiles%\zombie zero\resjpn.dll
- %ProgramFiles%\zombie zero\ncfootrst.exe
- %ProgramFiles%\zombie zero\cssysinfo_1.~cst
- %ProgramFiles%\zombie zero\cssysinfo_2.~cst
- %ProgramFiles%\zombie zero\drivers\imhdrv6.sys
- %ProgramFiles%\zombie zero\drivers\nptdimon.sys
- %ProgramFiles%\zombie zero\drivers\x64\filescan.sys
- %ProgramFiles%\zombie zero\drivers\x64\imhdrv6.sys
- %ProgramFiles%\zombie zero\drivers\x64\nptdimon.sys
- %ProgramFiles%\zombie zero\drivers\xp\filescan.sys
- %ProgramFiles%\zombie zero\x64\bdcore.dll
- %ProgramFiles%\zombie zero\drivers\xp\imhdrv.sys
- %ProgramFiles%\zombie zero\x64\bcgcbpro2900u100.dll
- %ProgramFiles%\zombie zero\x64\bdupdateservicecom.dll
- %ProgramFiles%\zombie zero\x64\oemuninstall.dll
- %ProgramFiles%\zombie zero\x64\avxdisk.dll
- %ProgramFiles%\zombie zero\x64\bdardrv.dll
- %ProgramFiles%\zombie zero\x64\bdarw.dll
- %ProgramFiles%\zombie zero\drivers\xp\nptdimon.inf
- %ProgramFiles%\zombie zero\drivers\filescan.sys
- %ProgramFiles%\zombie zero\drivers\xp\icc_c.inf
- %ProgramFiles%\zombie zero\drivers\xp\icc.inf
- %ProgramFiles%\zombie zero\drivers\xp\filescan.inf
- %ProgramFiles%\zombie zero\csrst_msg_1033.ini
- %ProgramFiles%\zombie zero\csrst_msg_1041.ini
- %ProgramFiles%\zombie zero\csrst_msg_1042.ini
- %ProgramFiles%\zombie zero\drivers\filescan.cat
- %ProgramFiles%\zombie zero\drivers\imhdrv6.cat
- %ProgramFiles%\zombie zero\drivers\nptdimon.cat
- %ProgramFiles%\zombie zero\x64\bdquar.dll
- %ProgramFiles%\zombie zero\drivers\x64\imhdrv6.cat
- %ProgramFiles%\zombie zero\drivers\x64\filescan.cat
- %ProgramFiles%\zombie zero\drivers\filescan.inf
- %ProgramFiles%\zombie zero\drivers\imhdrv6.inf
- %ProgramFiles%\zombie zero\drivers\nptdimon.inf
- %ProgramFiles%\zombie zero\drivers\x64\filescan.inf
- %ProgramFiles%\zombie zero\drivers\x64\imhdrv6.inf
- %ProgramFiles%\zombie zero\drivers\x64\nptdimon.inf
- %ProgramFiles%\zombie zero\cstask1000_3.~cst
- %ProgramFiles%\zombie zero\drivers\x64\nptdimon.cat
- %ProgramFiles%\zombie zero\log\20210719\zzero_error_2844.log
- %ProgramFiles%\zombie zero\util.exe
- %ProgramFiles%\zombie zero\x86\mfcm100.dll
- %ProgramFiles%\zombie zero\x86\mfc100u.dll
- %ProgramFiles%\zombie zero\x86\mfc100.dll
- %ProgramFiles%\zombie zero\x86\gzfltum.dll
- %ProgramFiles%\zombie zero\x86\bdupdateservicecom.dll
- %ProgramFiles%\zombie zero\x86\bdsmartdb.dll
- %ProgramFiles%\zombie zero\x86\bdquar.dll
- %ProgramFiles%\zombie zero\x86\bdcore.dll
- %ProgramFiles%\zombie zero\x86\bdardrv.dll
- %ProgramFiles%\zombie zero\x86\msvcp100.dll
- %ProgramFiles%\zombie zero\x86\bcgcbpro2900u100.dll
- %ProgramFiles%\zombie zero\x86\avxdisk.dll
- %ProgramFiles%\zombie zero\x64\trufos.dll
- %ProgramFiles%\zombie zero\x64\scan.dll
- %ProgramFiles%\zombie zero\x64\oemuninstall.dll
- %ProgramFiles%\zombie zero\x64\msvcr100.dll
- %ProgramFiles%\zombie zero\x64\msvcp100.dll
- %ProgramFiles%\zombie zero\x86\bdarw.dll
- %ProgramFiles%\zombie zero\drivers\nptdimon.sys
- %ProgramFiles%\zombie zero\x86\msvcr100.dll
- %ProgramFiles%\zombie zero\data\requestdb.db-journal
- %TEMP%\nsm4f49.tmp\version.dll
- %TEMP%\nsm4f49.tmp\userinfo.dll
- %TEMP%\nsm4f49.tmp\system.dll
- %TEMP%\nsm4f49.tmp\nsprocess.dll
- %TEMP%\nsm4f49.tmp\nsexec.dll
- %ProgramFiles%\zombie zero\data\policydb.db-journal
- %WINDIR%\temp\uddec13.tmp
- %ProgramFiles%\zombie zero\x64\mfcm100u.dll
- %ProgramFiles%\zombie zero\x86\mfcm100u.dll
- %ProgramFiles%\zombie zero\csrst_msg_1042.ini
- %ProgramFiles%\zombie zero\csrst_msg_1041.ini
- %ProgramFiles%\zombie zero\csrst_msg_1033.ini
- %ProgramFiles%\zombie zero\cstask1000_3.~cst
- %ProgramFiles%\zombie zero\cssysinfo_2.~cst
- %ProgramFiles%\zombie zero\cssysinfo_1.~cst
- %ProgramFiles%\zombie zero\x86\trufos.dll
- %ProgramFiles%\zombie zero\x86\scan.dll
- %ProgramFiles%\zombie zero\ssl.cer
- %ProgramFiles%\zombie zero\x86\oemuninstall.dll
- %ProgramFiles%\zombie zero\x64\mfcm100.dll
- %ProgramFiles%\zombie zero\x64\mfc100u.dll
- %ProgramFiles%\zombie zero\x64\mfc100.dll
- %ProgramFiles%\zombie zero\drivers\x64\filescan.sys
- %ProgramFiles%\zombie zero\drivers\xp\filescan.sys
- %ProgramFiles%\zombie zero\drivers\xp\filescan.inf
- %ProgramFiles%\zombie zero\drivers\x64\nptdimon.sys
- %ProgramFiles%\zombie zero\drivers\x64\nptdimon.inf
- %ProgramFiles%\zombie zero\drivers\x64\nptdimon.cat
- %ProgramFiles%\zombie zero\drivers\x64\imhdrv6.sys
- %ProgramFiles%\zombie zero\drivers\x64\imhdrv6.inf
- %ProgramFiles%\zombie zero\data\zzerodb.db-journal
- %ProgramFiles%\zombie zero\drivers\xp\icc_c.inf
- %ProgramFiles%\zombie zero\drivers\x64\filescan.inf
- %ProgramFiles%\zombie zero\drivers\x64\filescan.cat
- %ProgramFiles%\zombie zero\resjpn.dll
- %ProgramFiles%\zombie zero\reskor.dll
- %ProgramFiles%\zombie zero\zzerosrvc.exe
- %ProgramFiles%\zombie zero\zzero.exe
- %ProgramFiles%\zombie zero\regsvc.exe
- %ProgramFiles%\zombie zero\wdfcoinstaller01009.dll
- %ProgramFiles%\zombie zero\drivers\x64\imhdrv6.cat
- %ProgramFiles%\zombie zero\npcore.cer
- %ProgramFiles%\zombie zero\drivers\xp\imhdrv.sys
- %ProgramFiles%\zombie zero\drivers\filescan.cat
- %ProgramFiles%\zombie zero\drivers\xp\nptdimon.inf
- %ProgramFiles%\zombie zero\x64\gzfltum.dll
- %ProgramFiles%\zombie zero\x64\bdupdateservicecom.dll
- %ProgramFiles%\zombie zero\x64\bdsmartdb.dll
- %ProgramFiles%\zombie zero\x64\bdquar.dll
- %ProgramFiles%\zombie zero\x64\bdcore.dll
- %ProgramFiles%\zombie zero\x64\bdarw.dll
- %ProgramFiles%\zombie zero\x64\bdardrv.dll
- %ProgramFiles%\zombie zero\drivers\xp\nptdimon.sys
- %ProgramFiles%\zombie zero\x64\bcgcbpro2900u100.dll
- %ProgramFiles%\zombie zero\drivers\xp\icc.inf
- %ProgramFiles%\zombie zero\drivers\nptdimon.inf
- %ProgramFiles%\zombie zero\drivers\nptdimon.cat
- %ProgramFiles%\zombie zero\drivers\imhdrv6.sys
- %ProgramFiles%\zombie zero\drivers\imhdrv6.inf
- %ProgramFiles%\zombie zero\drivers\imhdrv6.cat
- %ProgramFiles%\zombie zero\drivers\filescan.sys
- %ProgramFiles%\zombie zero\drivers\filescan.inf
- %ProgramFiles%\zombie zero\x64\avxdisk.dll
- %WINDIR%\temp\udd313e.tmp
- <DRIVERS>\sete4a3.tmp в <DRIVERS>\filescan.sys
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- %ProgramFiles%\zombie zero\util.exe
- %ProgramFiles%\zombie zero\wdfcoinstaller01009.dll
- %ProgramFiles%\zombie zero\regsvc.exe
- %ProgramFiles%\zombie zero\zzero.exe
- %ProgramFiles%\zombie zero\zzerosrvc.exe
- %ProgramFiles%\zombie zero\reskor.dll
- %ProgramFiles%\zombie zero\resjpn.dll
- %ProgramFiles%\zombie zero\data\policydb.db-journal
- %ProgramFiles%\zombie zero\data\requestdb.db-journal
- %ProgramFiles%\zombie zero\data\zzerodb.db-journal
- '%ProgramFiles%\zombie zero\regsvc.exe' -u
- '%ProgramFiles%\zombie zero\regsvc.exe' -i
- '%ProgramFiles%\zombie zero\regsvc.exe' -stop
- '%ProgramFiles%\zombie zero\regsvc.exe' -start
- '%ProgramFiles%\zombie zero\regsvc.exe'
- '%ProgramFiles%\zombie zero\zzerosrvc.exe'
- '%ProgramFiles%\zombie zero\zzero.exe'
- '<SYSTEM32>\fltmc.exe' unload filescan' (со скрытым окном)
- '%ProgramFiles%\zombie zero\regsvc.exe' -u' (со скрытым окном)
- '%ProgramFiles%\zombie zero\regsvc.exe' -i' (со скрытым окном)
- '<SYSTEM32>\net.exe' stop FileScan' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' setupapi.dll,InstallHinfSection DefaultUninstall 0 %ProgramFiles%\Zombie ZERO\FileScan.inf' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' setupapi.dll,InstallHinfSection DefaultInstall 0 %ProgramFiles%\Zombie ZERO\FileScan.inf' (со скрытым окном)
- '%ProgramFiles%\zombie zero\regsvc.exe' -stop' (со скрытым окном)
- '%ProgramFiles%\zombie zero\regsvc.exe' -start' (со скрытым окном)
- '<SYSTEM32>\fltmc.exe' unload filescan
- '<SYSTEM32>\net1.exe' stop FileScan
- '<SYSTEM32>\rundll32.exe' setupapi.dll,InstallHinfSection DefaultUninstall 0 %ProgramFiles%\Zombie ZERO\FileScan.inf
- '<SYSTEM32>\runonce.exe' -r
- '<SYSTEM32>\grpconv.exe' -o
- '<SYSTEM32>\rundll32.exe' setupapi.dll,InstallHinfSection DefaultInstall 0 %ProgramFiles%\Zombie ZERO\FileScan.inf