Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\e0vnz3wk] 'ImagePath' = '%WINDIR%\e0vnz3wk.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\e0vnz3wk] 'Start' = '00000001'
- 'C:\QQPCDownload45865.exe' (загружен из сети Интернет)
- 'C:\56903abv_1202000680.exe' (загружен из сети Интернет)
- 'C:\rav3490099.exe' (загружен из сети Интернет)
- 'C:\QQPCDownload45865.exe'
- 'C:\56903abv_1202000680.exe'
- 'C:\rav3490099.exe'
- ClassName: '' WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: '' WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass' WindowName: ''
- ClassName: '' WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'GBDYLLO' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: 'FilemonClass' WindowName: ''
- ClassName: 'pediy06' WindowName: ''
- C:\QQPCDownload45865.exe
- %WINDIR%\SSL\cert.db
- %WINDIR%\SSL\Sample CA 2.cer
- C:\56903abv_1202000680.exe
- %WINDIR%\e0vnz3wk.sys
- %WINDIR%\yyqg.dll
- C:\rav3490099.exe
- %WINDIR%\e0vnz3wk.sys
- 'localhost':1044
- 'localhost':1045
- 'ha#.#ixihz.com':7518
- 'dl###6.qq.com':80
- 'www.92##s.com':80
- '10#.#.232.99':80
- '12#.#25.114.144':80
- http://dl###6.qq.com/invc/xfspeed/qqpcmgr/download/QQPCDownload45865.exe
- http://www.ba##u.com/ via 12#.#25.114.144
- http://www.92##s.com/
- http://www.92##s.com/gx/fzgx.txt
- http://10#.#.232.99/pl/aadf1134ci907/rav3490099.exe
- http://w.#.#aidu.com/go/full/201/1202000680 via 12#.#25.114.144
- DNS ASK www.ba##u.com
- DNS ASK ha#.#ixihz.com
- DNS ASK dl###6.qq.com
- DNS ASK www.92##s.com
- DNS ASK w.#.#aidu.com
- ClassName: 'ToolbarWindow32' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'SysPager' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'TrayNotifyWnd' WindowName: ''