Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\uuuvvvvvv.sys] 'ImagePath' = '%TEMP%\uuuvvvvvv.sys'
- 'uuuvvvvvv.sys' %TEMP%\uuuvvvvvv.sys
- <Текущая директория>\aaaaa.exe
- %TEMP%\uuuvvvvvv.sys
- %WINDIR%\temp\udd57c0.tmp
- %WINDIR%\temp\udd57c0.tmp
- 'wt.###oweinet.com':80
- 'ww##.#haoweinet.com':80
- 'd1#######stzrp.cloudfront.net':80
- 'br###-jar.com':443
- http://wt.###oweinet.com/shikong_new/login.asp
- http://ww##.#haoweinet.com/
- http://d1#######stzrp.cloudfront.net/themes/saledefault.css
- http://d1#######stzrp.cloudfront.net/themes/assets/style.css
- http://d1#######stzrp.cloudfront.net/themes/assets/zeropark.css
- 'br###-jar.com':443
- DNS ASK wt.###oweinet.com
- DNS ASK ww##.#haoweinet.com
- DNS ASK d1#######stzrp.cloudfront.net
- DNS ASK br###-jar.com
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<Текущая директория>\aaaaa.exe' -run <Полный путь к файлу>