Техническая информация
- [HKLM\System\CurrentControlSet\Services\baby] 'ImagePath' = '<SYSTEM32>\PastgooZ3.sys'
- 'baby' <SYSTEM32>\PastgooZ3.sys
- %WINDIR%\syswow64\pastgooz3.sys
- %WINDIR%\internet explorer.exe
- %HOMEPATH%\desktop\internet explorer.lnk
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\0y9o17dr\dnserrordiagoff_weboc[1]
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\bm8skz0v\errorpagetemplate[1]
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %WINDIR%\syswow64\pastgooz3.sys
- 'cf##n.com':80
- http://cf##n.com/aa.htm
- DNS ASK cf##n.com
- DNS ASK br###y168.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''