Техническая информация
- [HKCU\Software\Classes\discord-1025012895865651262\shell\open\command] '' = '<Полный путь к файлу>'
- [HKLM\System\CurrentControlSet\Services\GHOST] 'ImagePath' = '<Текущая директория>\GHOST.sys'
- 'GHOST' <Текущая директория>\GHOST.sys
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- <Текущая директория>\ghost.sys
- %WINDIR%\temp\udd7f0e.tmp
- %WINDIR%\temp\udd8759.tmp
- %WINDIR%\temp\udd8f36.tmp
- %WINDIR%\temp\udd9714.tmp
- %WINDIR%\temp\udd9ef1.tmp
- %WINDIR%\temp\udda6ce.tmp
- %WINDIR%\temp\udd7f0e.tmp
- %WINDIR%\temp\udd8759.tmp
- %WINDIR%\temp\udd8f36.tmp
- %WINDIR%\temp\udd9714.tmp
- %WINDIR%\temp\udd9ef1.tmp
- %WINDIR%\temp\udda6ce.tmp
- DNS ASK cd#.##scordapp.com
- ClassName: '18467-41' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c Color F
- '<SYSTEM32>\cmd.exe' /c MODE Con Cols=56 lines=16
- '<SYSTEM32>\mode.com' Con Cols=56 lines=16