Техническая информация
- [HKLM\System\CurrentControlSet\Services\I00545457K] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\I00545457K] 'ImagePath' = '<SYSTEM32>\svchost.exe -k svchost'
- [HKLM\SYSTEM\CurrentControlSet\Services\I00545457K\Parameters] 'ServiceDll' = '%ProgramFiles%\sb.dll'
- 'I00545457K' <SYSTEM32>\svchost.exe -k svchost
- 'tunnel' system32\DRIVERS\tunnel.sys
- %ProgramFiles%\sb.dll
- 'us##.#zone.qq.com':80
- 'us##.#zone.qq.com':443
- http://us##.#zone.qq.com/184920419
- 'us##.#zone.qq.com':443
- DNS ASK us##.#zone.qq.com
- '%WINDIR%\syswow64\svchost.exe' -k svchost