Техническая информация
- [HKLM\System\CurrentControlSet\Services\ReCdF44CdF] 'ImagePath' = '<DRIVERS>\ReCdF44CdF'
- [HKLM\System\CurrentControlSet\Services\Repvs36pvs] 'ImagePath' = '<DRIVERS>\Repvs36pvs'
- 'ReCdF44CdF' <DRIVERS>\ReCdF44CdF
- 'Repvs36pvs' <DRIVERS>\Repvs36pvs
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %WINDIR%\syswow64\drivers\trlfwnao.dll
- %WINDIR%\syswow64\drivers\gevitdnx.dll
- <DRIVERS>\recdf44cdf
- %WINDIR%\temp\udd943.tmp
- <DRIVERS>\repvs36pvs
- %WINDIR%\temp\udd1094.tmp
- %WINDIR%\syswow64\drivers\gevitdnx.dll
- <DRIVERS>\recdf44cdf
- <DRIVERS>\repvs36pvs
- %WINDIR%\syswow64\drivers\gevitdnx.dll
- %WINDIR%\temp\udd943.tmp
- %WINDIR%\temp\udd1094.tmp
- 'vi##.eydata.net':443
- '12#.#21.130.249':10886
- http://12#.###.130.249:10886/yun.txt via 12#.#21.130.249
- http://12#.###.130.249:10886/.106 via 12#.#21.130.249
- http://12#.###.130.249:10886/yun9.txt via 12#.#21.130.249
- 'vi##.eydata.net':443
- DNS ASK vi##.eydata.net
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''