Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{06479FBD-B7F4-E4BF-7FBF-CDD5E2D81431}] 'stubpath' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\NdisFileServices32] 'Start' = '00000002'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\Bifrost\server.exe
- <DRIVERS>\ejsrqn.sys
- %APPDATA%\addons.dat
- <SYSTEM32>\wmdrtc32.dl_
- <SYSTEM32>\wmdrtc32.dll
- %APPDATA%\addons.dat
- <SYSTEM32>\Bifrost\server.exe
- <DRIVERS>\ejsrqn.sys
- 'hi#####migo.no-ip.info':81
- 'www.in####1ongung.info':80
- 'fu#####bad.zapto.org':81
- 'www.bp##02.com':80
- www.in####1ongung.info/t_100_v400/?rn#######################
- www.bp##02.com/t_100_v400/?rn#######################
- DNS ASK www.bp##02.com
- DNS ASK hi#####migo.no-ip.info
- DNS ASK www.in####1ongung.info
- DNS ASK www.g1#####vns3sdsal.info
- DNS ASK www.microsoft.com
- DNS ASK fu#####bad.zapto.org
- '<IP-адрес в локальной сети>':1035
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Indicator' WindowName: ''