Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\dmboot] 'Start' = '00000002'
- <DRIVERS>\dmboot.sys файлом <DRIVERS>\dmboot.txt
- '<SYSTEM32>\attrib.exe' <DRIVERS>\dmboot.sys -A -R -H
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\erdans.bat" "
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- iexplore.exe
- <SYSTEM32>\TdAtOnce_Now.dll
- <SYSTEM32>\apx.dll
- <DRIVERS>\dmboot.txt
- %TEMP%\erdans.bat
- %TEMP%\erdans.bat
- <DRIVERS>\dmboot.sys
- 'to####.jzads.com':6789
- 'localhost':1036
- DNS ASK to####.jzads.com
- ClassName: 'IEFrame' WindowName: '(null)'