Техническая информация
- [HKLM\System\CurrentControlSet\Services\79918DF4] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\79918DF4] 'ImagePath' = '<DRIVERS>\79918DF4.sys'
- '79918DF4' <DRIVERS>\79918DF4.sys
- [HKLM\System\CurrentControlSet\Services\79918DF4] 'Group' = 'FSFilter Activity Monitor'
- %APPDATA%\chromesetup.exe
- <DRIVERS>\79918df4.sys
- %WINDIR%\temp\udd6364.tmp
- %WINDIR%\temp\udd6b51.tmp
- %WINDIR%\temp\udd734d.tmp
- %WINDIR%\temp\udd7b2b.tmp
- %WINDIR%\temp\udd8318.tmp
- %WINDIR%\temp\udd8af5.tmp
- %WINDIR%\temp\udd6364.tmp
- %WINDIR%\temp\udd6b51.tmp
- %WINDIR%\temp\udd734d.tmp
- %WINDIR%\temp\udd7b2b.tmp
- %WINDIR%\temp\udd8318.tmp
- %WINDIR%\temp\udd8af5.tmp
- %APPDATA%\chromesetup.exe
- 'dl.##romel.cn':67
- 'tj.##romel.cn':67
- 'tj.#oxe7.cc':799
- http://dl.###omel.cn:67/ChromeSetup.exe via dl.##romel.cn
- http://tj.###omel.cn:67/tongji.php?id######################################################################### via tj.##romel.cn
- http://tj.###omel.cn:67/mac/jvyttj.html via tj.##romel.cn
- DNS ASK dl.##romel.cn
- DNS ASK tj.##romel.cn
- DNS ASK tj.#oxe7.cc
- '%APPDATA%\chromesetup.exe'
- '%WINDIR%\syswow64\cmd.exe' /c del %APPDATA%\CHROME~1.EXE > nul' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c del %APPDATA%\CHROME~1.EXE > nul