Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Cikdjo uaeqka] 'Start' = '00000002'
- '%PROGRAM_FILES%\Windows NT\Terms.EXE'
- '%WINDIR%\Temp\SB360.exe'
- '%WINDIR%\Temp\їнґшЛўЧкГЬВлГЬ±ЈµцУг.exe'
- %PROGRAM_FILES%\Windows NT\Terms.EXE
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\1928885900[1]
- %WINDIR%\Temp\SB360.exe
- %WINDIR%\Temp\їнґшЛўЧкГЬВлГЬ±ЈµцУг.exe
- 'localhost':1040
- 'us##.#zone.qq.com':80
- 'if####.ip138.com':80
- '19#####900.f3322.org':80
- us##.#zone.qq.com/1928885900
- if####.ip138.com/ic.asp
- DNS ASK us##.#zone.qq.com
- DNS ASK 19#####900.f3322.org
- DNS ASK if####.ip138.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'