Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SafeVaccine' = '%PROGRAM_FILES%\safevaccine\safevaccine_starter.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\sv10tkx] 'Start' = '00000002'
- %PROGRAM_FILES%\safevaccine\sv30mac.exe -svsk646
- %PROGRAM_FILES%\safevaccine\sv30mac.exe -svct889
- %PROGRAM_FILES%\safevaccine\safevaccine_starter.exe
- %PROGRAM_FILES%\safevaccine\sv30mac.exe -svi370
- NtOpenKey, драйвер-обработчик: sv10tkx.sys
- NtSetInformationFile, драйвер-обработчик: sv10tkx.sys
- NtSetValueKey, драйвер-обработчик: sv10tkx.sys
- NtOpenFile, драйвер-обработчик: sv10tkx.sys
- NtCreateFile, драйвер-обработчик: sv10tkx.sys
- NtDeleteKey, драйвер-обработчик: sv10tkx.sys
- NtDeleteValueKey, драйвер-обработчик: sv10tkx.sys
- <DRIVERS>\sv10tkx.sys
- %PROGRAM_FILES%\safevaccine\sv30mac.exe
- %PROGRAM_FILES%\safevaccine\SfShotCut.exe
- %WINDIR%\sv30mac.exe
- %WINDIR%\safevaccine_uninstaller.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\count[1].php
- %PROGRAM_FILES%\safevaccine\Uninstall.exe
- %PROGRAM_FILES%\safevaccine\ver.ini
- %PROGRAM_FILES%\safevaccine\safevaccine_starter.exe
- %PROGRAM_FILES%\safevaccine\safevaccine.exe
- %PROGRAM_FILES%\safevaccine\license.txt
- %PROGRAM_FILES%\safevaccine\safevaccine.dll
- %PROGRAM_FILES%\safevaccine\safevaccine_pdb.sa_
- %PROGRAM_FILES%\safevaccine\safevaccine_db.sa_
- 'sa###accine.net':80
- sa###accine.net/count.php?pi############################
- DNS ASK sa###accine.net