Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\Google\Libs\WR64.sys'
- 'WinRing0_1_2_0' %APPDATA%\Google\Libs\WR64.sys
- <SYSTEM32>\conhost.exe
- %APPDATA%\google\libs\wr64.sys
- %APPDATA%\google\libs\g.log
- %TEMP%\7493.tmp
- DNS ASK rx.###ineable.com
- DNS ASK re##ry.co
- DNS ASK su###udio.su
- '<SYSTEM32>\cmd.exe' /c mkdir "%APPDATA%\Google\Libs\" & wmic PATH Win32_VideoController GET Name, VideoProcessor > "%APPDATA%\Google\Libs\g.log"
- '<SYSTEM32>\wbem\wmic.exe' PATH Win32_VideoController GET Name, VideoProcessor