Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\NalDrv] 'ImagePath' = '<Текущая директория>\NalDrv.sys'
- [<HKLM>\System\CurrentControlSet\Services\PROCEXP152] 'ImagePath' = '%TEMP%\PROCEXP152.sys'
- 'NalDrv' <Текущая директория>\NalDrv.sys
- 'PROCEXP152' %TEMP%\PROCEXP152.sys
- %WINDIR%\softwaredistribution\download\ddtpp.sys
- %WINDIR%\softwaredistribution\download\ddtpp.exe
- <Текущая директория>\naldrv.sys
- %TEMP%\procexp152.sys
- %TEMP%\procexp152.sys
- <Текущая директория>\naldrv.sys
- %WINDIR%\softwaredistribution\download\ddtpp.sys
- %WINDIR%\softwaredistribution\download\ddtpp.exe
- 'cd#.##scordapp.com':443
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- '%WINDIR%\softwaredistribution\download\ddtpp.exe' -map %WINDIR%\SoftwareDistribution\Download\DDtpP.sys
- '%WINDIR%\softwaredistribution\download\ddtpp.exe' -map %WINDIR%\SoftwareDistribution\Download\DDtpP.sys' (со скрытым окном)