Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\aliserv] 'start' = '00000001'
- '<SYSTEM32>\spoolsv.exe'
- <DRIVERS>\aliserv3.sys
- %TEMP%\ali1.tmp
- %TEMP%\ali2.tmp
- %TEMP%\ali2.tmp
- 'bs##ys.com':80
- DNS ASK bs##ys.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'