Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'CnsMin' = 'Rundll32.exe %WINDIR%\Downloaded Program Files\CnsMin.dll,Rundll32'
- <SYSTEM32>\rundll32.exe %WINDIR%\Downloaded Program Files\patch23.dll,DllUnregisterServer
- <SYSTEM32>\rundll32.exe %WINDIR%\Downloaded Program Files\CnsMin.dll,Rundll32
- <SYSTEM32>\rundll32.exe "%WINDIR%\Downloaded program files\patch23.dll",DllRegisterServer
- %WINDIR%\Downloaded Program Files\patch23.dll
- %WINDIR%\Downloaded Program Files\insthlper.dll
- %WINDIR%\Downloaded Program Files\cnsmin.dll
- %TEMP%\nsr3.tmp\wmpns.ini
- %TEMP%\nsr3.tmp\wmpns.dll
- %TEMP%\nsb2.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\wmpns[1].ini
- %TEMP%\nsr3.tmp\System.dll
- %TEMP%\nsr3.tmp\wmpns.ini
- %WINDIR%\Downloaded Program Files\patch23.dll
- %TEMP%\nsr3.tmp\System.dll
- %TEMP%\nsr3.tmp\wmpns.dll
- %WINDIR%\Downloaded Program Files\insthlper.dll
- 'do####ad.3721.com':80
- 'localhost':1037
- do####ad.3721.com/download/wmpns.ini
- DNS ASK do####ad.3721.com