Техническая информация
- [HKLM\System\CurrentControlSet\Services\360natnon.sys] 'ImagePath' = '<SYSTEM32>\360natnon.sys'
- [HKLM\System\CurrentControlSet\Services\DelFile] 'ImagePath' = '%WINDIR%\SysWOW64\drivers\DelFile.sys'
- '360natnon.sys' <SYSTEM32>\360natnon.sys
- 'DelFile' %WINDIR%\SysWOW64\drivers\DelFile.sys
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\syswow64\360natnon.sys
- %WINDIR%\syswow64\drivers\del.exe
- %WINDIR%\syswow64\drivers\delfile.sys
- %WINDIR%\syswow64\drivers\qqprotect.sys
- %WINDIR%\syswow64\drivers\qqprà ¶æá´¦à Г.exe
- %WINDIR%\syswow64\360natnon.sys
- %WINDIR%\syswow64\drivers\del.exe
- %WINDIR%\syswow64\360natnon.sys
- %WINDIR%\syswow64\drivers\del.exe
- %WINDIR%\syswow64\drivers\delfile.sys
- %WINDIR%\syswow64\drivers\qqprà ¶æá´¦à Г.exe
- '%WINDIR%\syswow64\drivers\del.exe' "<DRIVERS>\QQProtect.sys"
- '%WINDIR%\syswow64\drivers\qqprà ¶æá´¦à Г.exe'
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\drivers\del.exe' "<DRIVERS>\QQProtect.sys" (со скрытым окном)