Техническая информация
- [HKLM\software\Wow6432Node\microsoft\windows\CurrentVersion\Run] 'Lshuai' = '<Полный путь к файлу>'
- [HKLM\System\CurrentControlSet\Services\vhdmp] 'ImagePath' = 'system32\DRIVERS\vhdmp.sys'
- [HKLM\System\CurrentControlSet\Services\Disk] 'Start' = '00000000'
- 'vhdmp' system32\DRIVERS\vhdmp.sys
- 'disk' system32\DRIVERS\disk.sys
- %TEMP%\c712b.tmp
- %TEMP%\c712a.tmp.vhd
- scsi#disk&ven_msft&prod_virtual_disk#2&1f4adffe&0&000001#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
- physicaldrive2
- 'rm###########m4z470wio.mysql.rds.aliyuncs.com':3306
- 'rm###########m4z470wio.mysql.rds.aliyuncs.com':3306
- DNS ASK rm###########m4z470wio.mysql.rds.aliyuncs.com
- ClassName: 'DINotifyWindowClass853' WindowName: 'DINotifyWindowName853'
- '%WINDIR%\syswow64\sc.exe' stop ShellHWDetection (со скрытым окном)
- '%WINDIR%\syswow64\diskpart.exe' -s %TEMP%\c712b.tmp (со скрытым окном)
- '<SYSTEM32>\vds.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\newdev.dll,pDiDeviceInstallNotification \\.\pipe\PNP_Device_Install_Pipe_1.{a04ef739-66a5-4432-a7bb-35a83f32442e} "(null)"
- '<SYSTEM32>\dinotify.exe' pnpui.dll,SimplifiedDINotification