Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\10012542.sys] 'ImagePath' = '%WINDIR%\10012542.sys'
- [<HKLM>\System\CurrentControlSet\Services\netfilter2] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\netfilter2] 'ImagePath' = 'system32\drivers\netfilter2.sys'
- '10012542.sys' %WINDIR%\10012542.sys
- 'netfilter2' system32\drivers\netfilter2.sys
- %WINDIR%\syswow64\cmd.exe
- %WINDIR%\10012542.sys
- %WINDIR%\temp\udd89e7.tmp
- %WINDIR%\syswow64\xydsoftwpe.dll
- %WINDIR%\syswow64\nfapi.dll
- <DRIVERS>\netfilter2.sys
- %WINDIR%\temp\udd9981.tmp
- %WINDIR%\temp\udd89e7.tmp
- %WINDIR%\temp\udd9981.tmp
- %WINDIR%\syswow64\xydsoftwpe.dll в %TEMP%\1158650\....\temporaryfile
- '%WINDIR%\syswow64\cmd.exe'