Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SiSPower ' = '%WINDIR%\RunDlll32.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SiSPower ' = '%WINDIR%\RunDlll32.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\zfdzecm] 'Start' = '00000000'
- C:\wxdhtq.txt
- <DRIVERS>\wmiq.sys
- %WINDIR%\RunDlll32.exe
- 'ad###h.ueuo.com':80
- ad###h.ueuo.com/count.php
- DNS ASK ad###h.ueuo.com
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'
- ClassName: 'Indicator' WindowName: '(null)'