Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SQ Platform' = '%TEMP%\services_8004.exe ?(?3?)? ?,??????'
- [<HKLM>\SYSTEM\ControlSet001\Services\YQAQTYBG] 'ImagePath' = '<DRIVERS>\YQAQTYBG.sys'
- '%TEMP%\·гмбЎ¤ЎоЎп-·гТ¶_±©З№УўРЫДЪЗ¶ґ°їЪ.exe'
- '%TEMP%\services_8004.exe'
- NtReadVirtualMemory, драйвер-обработчик: YQAQTYBG.sys
- NtWriteVirtualMemory, драйвер-обработчик: YQAQTYBG.sys
- NtOpenProcess, драйвер-обработчик: YQAQTYBG.sys
- NtQuerySystemInformation, драйвер-обработчик: mydri.sys
- %TEMP%\·гмбЎ¤ЎоЎп-·гТ¶_±©З№УўРЫДЪЗ¶ґ°їЪ.exe
- %HOMEPATH%\Desktop\Лж±гїґїґ.lnk
- %TEMP%\services_8004.exe
- <SYSTEM32>\mydri.sys
- <DRIVERS>\YQAQTYBG.sys
- <SYSTEM32>\mydri.sys
- <DRIVERS>\YQAQTYBG.sys
- 'any':5555
- 'www.ke##pan.com':80
- www.ke##pan.com/space_fenghuo_5723.html
- DNS ASK k2.##kudown.com
- DNS ASK k3.##kudown.com
- DNS ASK k4.##kudown.com
- DNS ASK k1.##kudown.com
- DNS ASK www.ke##pan.com
- DNS ASK k.###udown.com
- DNS ASK pa#.#aidu.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'