Техническая информация
- [HKLM\System\CurrentControlSet\Services\BackInC] 'ImagePath' = '<SYSTEM32>\BackInC.sys'
- 'BackInC' <SYSTEM32>\\BackInC.sys
- %WINDIR%\syswow64\backinc.sys
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\syswow64\backinc.sys
- 'op##.baidu.com':80
- 'ba##u.com':443
- 'microsoft.com':80
- http://op##.baidu.com/special/time/
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- 'ba##u.com':443
- DNS ASK op##.baidu.com
- DNS ASK ba##u.com