Техническая информация
- [HKLM\Software\Wow6432Node\microsoft\Windows NT\CURRENTVERSION\WINDOWS] 'LoadAppInit_DLLs' = '00000001'
- [HKLM\Software\Wow6432Node\microsoft\Windows NT\CURRENTVERSION\WINDOWS] 'Appinit_Dlls' = 'nmklo'
- 'umbus' system32\DRIVERS\umbus.sys
- %TEMP%\qas46bf.tmp
- %WINDIR%\syswow64\cooper.mine
- %WINDIR%\syswow64\cccc
- %WINDIR%\syswow64\nmklo.dll
- %WINDIR%\syswow64\h7t.wt
- %WINDIR%\syswow64\ff4h.gy
- %WINDIR%\syswow64\hgtd.ruy
- <SYSTEM32>\microsoft\protect\s-1-5-20\d1ed5cb0-e6f2-4e81-be10-60d52fe7fe5a
- <SYSTEM32>\microsoft\protect\s-1-5-20\preferred
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\machinekeys\f686aace6942fb7f7ceb231212eef4a4_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
- %TEMP%\qas46bf.tmp
- %WINDIR%\syswow64\cccc
- DNS ASK si###opa.com
- DNS ASK pe###opa.com
- DNS ASK ne###opa.com
- '%WINDIR%\syswow64\wbem\wmic.exe' path win32_terminalservicesetting where (__Class!="") call setallowtsconnections 1 (со скрытым окном)