Техническая информация
- [HKLM\System\CurrentControlSet\Services\baby] 'ImagePath' = '<SYSTEM32>\PastRXPih.sys'
- 'baby' <SYSTEM32>\PastRXPih.sys
- %WINDIR%\syswow64\pastrxpih.sys
- %WINDIR%\internet explorer.exe
- %HOMEPATH%\desktop\internet explorer.lnk
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012023112520231126\index.dat
- %WINDIR%\syswow64\pastrxpih.sys
- 'cf##n.com':80
- DNS ASK cf##n.com
- DNS ASK br###y168.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''