Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\Iprip\] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Iprip\Parameters\] 'ServiceDll' = '<SYSTEM32>\liprip.dll'
- [HKLM\System\CurrentControlSet\Services\Iprip] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Iprip] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- 'Iprip' <SYSTEM32>\svchost.exe -k netsvcs
- %TEMP%\glcf69d.tmp
- %TEMP%\gljfb7e.tmp
- %TEMP%\glg408.tmp
- %WINDIR%\syswow64\~glh0000.tmp
- %WINDIR%\~glh0001.tmp
- %WINDIR%\inf\~glh0002.tmp
- C:\recycled\~glh0003.tmp
- %TEMP%\~glh0004.tmp
- %WINDIR%\syswow64\~glh0005.tmp
- C:\recycled\~glh0006.tmp
- %WINDIR%\inf\~glh0007.tmp
- %WINDIR%\help\~glh0008.tmp
- C:\recycled\~glh0009.tmp
- %TEMP%\set.exe
- %TEMP%\glg408.tmp
- %TEMP%\gljfb7e.tmp
- %TEMP%\glcf69d.tmp
- %WINDIR%\syswow64\~glh0000.tmp в %WINDIR%\syswow64\fsutk.dll
- %WINDIR%\~glh0001.tmp в %WINDIR%\kentgo.log
- %WINDIR%\inf\~glh0002.tmp в %WINDIR%\inf\optkec.inf
- C:\recycled\~glh0003.tmp в C:\recycled\qkf.dat
- %TEMP%\~glh0004.tmp в %TEMP%\set.exe
- %WINDIR%\syswow64\~glh0005.tmp в %WINDIR%\syswow64\liprip.dll
- C:\recycled\~glh0006.tmp в C:\recycled\lip.dat
- %WINDIR%\inf\~glh0007.tmp в %WINDIR%\inf\iplbk.inf
- %WINDIR%\help\~glh0008.tmp в %WINDIR%\help\fkhfu.chi
- C:\recycled\~glh0009.tmp в C:\recycled\ctv.dat
- '%TEMP%\set.exe'
- '%TEMP%\gljfb7e.tmp' <SYSTEM32>\fsutk.dll