Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\appsign4w_gl] 'ImagePath' = '"%CommonProgramFiles%\Wellbia.com\appsign4w_gl.exe"'
- [HKLM\SYSTEM\CurrentControlSet\Services\xhunter1] 'ImagePath' = '%WINDIR%\xhunter1.sys'
- 'appsign4w_gl' "%CommonProgramFiles%\Wellbia.com\appsign4w_gl.exe"
- 'appsign4w_gl' %CommonProgramFiles%\Wellbia.com\appsign4w_gl.exe
- 'xhunter1' %WINDIR%\xhunter1.sys
- %LOCALAPPDATA%\wellbia\<Имя файла>.exe.log
- %LOCALAPPDATA%\wellbia\ucsvc.exe
- %CommonProgramFiles%\wellbia.com\appsign4w_gl.exe
- %WINDIR%\xhunter1.sys
- xhunter1
- %WINDIR%\xhunter1.sys
- '52.##.174.42':80
- '%LOCALAPPDATA%\wellbia\ucsvc.exe' -run
- '%LOCALAPPDATA%\wellbia\ucsvc.exe' -install
- '%CommonProgramFiles%\wellbia.com\appsign4w_gl.exe'
- '%LOCALAPPDATA%\wellbia\ucsvc.exe' -install (со скрытым окном)