Техническая информация
- [HKLM\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcTEBhM.sys'
- [HKLM\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcZgiLp.sys'
- [HKLM\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcsAtVO.sys'
- [HKLM\System\CurrentControlSet\Services\abc2.0] 'ImagePath' = '%TEMP%\~abcBA5sB.sys'
- 'abc2.0' %TEMP%\~abcTEBhM.sys
- 'abc2.0' %TEMP%\~abcZgiLp.sys
- 'abc2.0' %TEMP%\~abcsAtVO.sys
- 'abc2.0' %TEMP%\~abcBA5sB.sys
- %TEMP%\~abcTEBhM.sys
- %TEMP%\~abcZgiLp.sys
- %TEMP%\wb164.exe
- %TEMP%\~abcsAtVO.sys
- %TEMP%\~abcBA5sB.sys
- %WINDIR%\syswow64\0406f1.dll
- %TEMP%\~abcTEBhM.sys
- %TEMP%\~abcZgiLp.sys
- %TEMP%\~abcsAtVO.sys
- %TEMP%\~abcBA5sB.sys
- %TEMP%\~abcTEBhM.sys
- %TEMP%\~abcZgiLp.sys
- %TEMP%\~abcsAtVO.sys
- %TEMP%\~abcBA5sB.sys
- %TEMP%\wb164.exe
- %HOMEPATH%\desktop\google chrome.lnk
- 'sp.###ove123.com':80
- '11#.#24.100.244':80
- http://sp.###ove123.com/NIP.dat
- http://sp.###ove123.com/yzxy.txt
- DNS ASK sp.###ove123.com
- DNS ASK cs.###ove123.com
- ClassName: '' WindowName: 'TPHelper.exe'
- '%TEMP%\wb164.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start %TEMP%\Wb164.exe (со скрытым окном)