Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\10009028.sys] 'ImagePath' = '%WINDIR%\10009028.sys'
- [<HKLM>\System\CurrentControlSet\Services\netfilter2] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\netfilter2] 'ImagePath' = 'system32\drivers\netfilter2.sys'
- '10009028.sys' %WINDIR%\10009028.sys
- 'netfilter2' system32\drivers\netfilter2.sys
- %WINDIR%\syswow64\cmd.exe
- %WINDIR%\10009028.sys
- %WINDIR%\temp\udde197.tmp
- %WINDIR%\syswow64\xydsoftwpe.dll
- %WINDIR%\syswow64\nfapi.dll
- <DRIVERS>\netfilter2.sys
- %WINDIR%\temp\uddfbbd.tmp
- %WINDIR%\temp\udde197.tmp
- %WINDIR%\temp\uddfbbd.tmp
- %WINDIR%\syswow64\xydsoftwpe.dll в %TEMP%\1380468\....\temporaryfile
- '%WINDIR%\syswow64\cmd.exe'