Техническая информация
- NtOpenProcess, драйвер-обработчик: superec.AntiOpenProcess.sys
- %TEMP%\skinh.she
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\read[1].php
- <SYSTEM32>\SkinH_EL.dll
- <SYSTEM32>\superec.AntiOpenProcess.sys
- <SYSTEM32>\superec.AntiOpenProcess.sys
- 'www.mi###iwg.com':80
- www.mi###iwg.com/read.php?ti###########
- DNS ASK www.mi###iwg.com
- ClassName: 'Shell_TrayWnd' WindowName: ''