Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\f5581e2b] 'Start' = '00000002'
- <SYSTEM32>\rundll32.exe "%CommonProgramFiles%\Microsoft Shared\Triedit\f5581e2b.dll",ServiceEntry
- %TEMP%\RCX1.tmp
- %CommonProgramFiles%\Microsoft Shared\Triedit\f5581e2b.dll
- %TEMP%\1b040_res.dll
- %ALLUSERSPROFILE%\DebugLog.log
- %TEMP%\1b040_res.zip
- %TEMP%\1b040_res.dll
- %TEMP%\1b040_res.zip
- 'by.#8aq.com':1433
- DNS ASK by.#8aq.com