Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunServices] 'ПµНіЧАГж№ЬАнЖч' = '%WINDIR%\sdqlyk \dwm.exe'
- '%WINDIR%\sdqlyk \dwm.exe' \dwm.exe
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 2
- '<SYSTEM32>\wscript.exe' "%TEMP%\19c5a.tmp.vbs"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cgi_personal_card[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\cgi_personal_card[1]
- %TEMP%\19c5a.tmp.vbs
- %WINDIR%\sdqlyk \dwm.exe
- %WINDIR%\sdqlyk \dwm.exe
- %TEMP%\19c5a.tmp.vbs
- '<IP-адрес в локальной сети>':4200
- 'r.###ne.qq.com':80
- 'localhost':1036
- r.###ne.qq.com/cgi-bin/user/cgi_personal_card?ui############
- r.###ne.qq.com/cgi-bin/user/cgi_personal_card?ui##
- DNS ASK r.###ne.qq.com
- ClassName: '(null)' WindowName: 'sdqlisagoodsoftware35498'