Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\TtboxulMJg7gWi] 'ImagePath' = '%TEMP%\TtboxulMJg7gWiX8pQxv.sys'
- [<HKLM>\System\CurrentControlSet\Services\DXUnz9DPyxIcTX] 'ImagePath' = '%TEMP%\DXUnz9DPyxIcTXr4Tfpm.sys'
- [<HKLM>\System\CurrentControlSet\Services\0sLB5uwlHV1bRx] 'ImagePath' = '%TEMP%\0sLB5uwlHV1bRxq29s6M.sys'
- 'TtboxulMJg7gWi' %TEMP%\TtboxulMJg7gWiX8pQxv.sys
- 'DXUnz9DPyxIcTX' %TEMP%\DXUnz9DPyxIcTXr4Tfpm.sys
- '0sLB5uwlHV1bRx' %TEMP%\0sLB5uwlHV1bRxq29s6M.sys
- %TEMP%\ttboxulmjg7gwix8pqxv.sys
- %WINDIR%\temp\udd2da4.tmp
- %TEMP%\dxunz9dpyxictxr4tfpm.sys
- %TEMP%\0slb5uwlhv1brxq29s6m.sys
- %WINDIR%\temp\udd2da4.tmp
- 'ne######erifly.ntoskr.com':80
- http://ne#######rifly.ntoskr.com.:80/verifly?ke########################## via ne######erifly.ntoskr.com
- DNS ASK ne######erifly.ntoskr.com