Техническая информация
- '<SYSTEM32>\svehosd.exe'
- '<SYSTEM32>\sohu.exe'
- NtWriteVirtualMemory, драйвер-обработчик: PXSI3ZV.sys
- NtReadVirtualMemory, драйвер-обработчик: PXSI3ZV.sys
- NtQuerySystemInformation, драйвер-обработчик: PXSI3ZV.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\thread[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tt336[2]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\1705313832[2]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\1705313832[1]
- <SYSTEM32>\svehosd.exe
- <SYSTEM32>\sohu.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tt336[1]
- <SYSTEM32>\PXSI3ZV.sys
- <DRIVERS>\etc\hosts
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\1705313832[1]
- <SYSTEM32>\PXSI3ZV.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tt336[1]
- 'localhost':1040
- 'yy.com':80
- 'localhost':1036
- 'www.tt##6.com':80
- yy.com/5336/1705313832
- www.tt##6.com/thread.php?fi####
- www.tt##6.com/
- DNS ASK yy.com
- DNS ASK www.tt##6.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''