Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = 'c:\bypjajpzf\start.lnk'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\start.lnk
- 'C:\bypjajpzf\csrss.exe' "c:\bypjajpzf\mydat.dll",InitSkin
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\shit[1].php
- C:\bypjajpzf\data.mdb
- C:\bypjajpzf\start.lnk
- C:\bypjajpzf\mydat.dll
- C:\bypjajpzf\csrss.exe
- <DRIVERS>\etc\hosts
- C:\bypjajpzf\data.mdb
- 'v.##yf.com':80
- 'v.##yf.com':5631
- v.##yf.com/shit.php
- DNS ASK v.##yf.com