Техническая информация
- [HKLM\System\CurrentControlSet\Services\boshiAnti] 'ImagePath' = '%TEMP%\5.5yyz.com.sys'
- 'boshiAnti' %TEMP%\5.5yyz.com.sys
- C:\fzyz.dll
- %TEMP%\7bb4.tmp
- %TEMP%\7cce.tmp
- %TEMP%\7d3c.tmp
- %TEMP%\5.5yyz.com.sys
- %TEMP%\7bb4.tmp
- %TEMP%\7cce.tmp
- %TEMP%\7d3c.tmp
- %TEMP%\5.5yyz.com.sys
- %TEMP%\5.5yyz.com.sys
- '17##6qq.com':80
- http://www.17##6qq.com/feige.txt
- DNS ASK 17##6qq.com