Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SbTool' = '"%ProgramFiles(x86)%\SbTool\SbTool.exe"'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SbTool' = '%ProgramFiles(x86)%\SbTool\SbTool.exe'
- %TEMP%\nsz1d12.tmp\nsprocess.dll
- %TEMP%\nsz1d12.tmp\uac.dll
- %ProgramFiles(x86)%\sbtool\sbtool.dll
- %ProgramFiles(x86)%\sbtool\sbtool.exe
- %TEMP%\nsz1d12.tmp\system.dll
- %ProgramFiles(x86)%\sbtool\uninstall.exe
- %TEMP%\nsz1d12.tmp\ipconfig.dll
- %TEMP%\nsz1d12.tmp\inetc.dll
- %TEMP%\nsz1d12.tmp\inetc.dll
- %TEMP%\nsz1d12.tmp\ipconfig.dll
- %TEMP%\nsz1d12.tmp\nsprocess.dll
- %TEMP%\nsz1d12.tmp\system.dll
- %TEMP%\nsz1d12.tmp\uac.dll
- '34.##9.100.209':443
- DNS ASK sb####.moreinside.co.kr
- DNS ASK wi###o.co.kr
- ClassName: '#32770' WindowName: ''
- '%ProgramFiles(x86)%\sbtool\sbtool.exe'
- '%WINDIR%\syswow64\regsvr32.exe' /u /s "%ProgramFiles(x86)%\STool\STool.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /u /s "%ProgramFiles(x86)%\WinPro\WinPro.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /u /s "%ProgramFiles(x86)%\EasyOn\EasyOn.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\SbTool\SbTool.dll" (со скрытым окном)