Техническая информация
- [HKLM\System\CurrentControlSet\Services\jxOAoPB] 'ImagePath' = '<DRIVERS>\jxOAoPB.sys'
- 'jxOAoPB' <DRIVERS>\jxOAoPB.sys
- %WINDIR%\explorer.exe
- <DRIVERS>\jxoaopb.sys
- %WINDIR%\temp\udd4817.tmp
- %TEMP%\de2lmyng.bat
- nul
- <DRIVERS>\jxoaopb.sys
- %WINDIR%\temp\udd4817.tmp
- <DRIVERS>\jxoaopb.sys
- 'cn.bing.com':80
- '47.##5.203.246':10179
- http://cn.bing.com/
- '47.##5.203.246':10179
- DNS ASK cn.bing.com
- DNS ASK wd#.#rmime.top
- DNS ASK sf###.hvhndv.top
- DNS ASK hs##.#uzbqmrecm.top
- '47.##5.205.93':10178
- '255.255.255.255':29352
- '<LOCALNET>.23.29':29353
- ClassName: 'ProgMan' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\De2lMYNg.bat""' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\De2lMYNg.bat""
- '<SYSTEM32>\ping.exe' -n 2 127.1