Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\appsign4w_gl] 'ImagePath' = '"%CommonProgramFiles%\Wellbia.com\appsign4w_gl.exe"'
- [HKLM\SYSTEM\CurrentControlSet\Services\xhunter1] 'ImagePath' = '%WINDIR%\xhunter1.sys'
- 'appsign4w_gl' "%CommonProgramFiles%\Wellbia.com\appsign4w_gl.exe"
- 'appsign4w_gl' %CommonProgramFiles%\Wellbia.com\appsign4w_gl.exe
- 'xhunter1' %WINDIR%\xhunter1.sys
- ClassName: 'OllyDBG', WindowName: ''
- %TEMP%\app39b5.tmp.exe
- %LOCALAPPDATA%\wellbia\app39b5.tmp.exe.log
- %LOCALAPPDATA%\wellbia\ucsvc.exe
- %CommonProgramFiles%\wellbia.com\appsign4w_gl.exe
- %WINDIR%\xhunter1.sys
- xhunter1
- %TEMP%\uncheater-system.log
- %WINDIR%\xhunter1.sys
- '52.##.174.42':80
- '34.##9.100.209':443
- ClassName: 'WinDbgFrameClass' WindowName: ''
- '%TEMP%\app39b5.tmp.exe' {DE90C4B1-FC66-4D17-A22B-31165D0C1759}
- '%LOCALAPPDATA%\wellbia\ucsvc.exe' -run
- '%LOCALAPPDATA%\wellbia\ucsvc.exe' -install
- '%CommonProgramFiles%\wellbia.com\appsign4w_gl.exe'
- '%LOCALAPPDATA%\wellbia\ucsvc.exe' -install (со скрытым окном)