Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\stisvc] 'Start' = '00000002'
- '<SYSTEM32>\net1.exe' start
- '<SYSTEM32>\systeminfo.exe'
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\svchost.exe' -k imgsvc
- '<SYSTEM32>\net1.exe' user
- %APPDATA%\Microsoft\Network\6B5A4607.CAB
- %WINDIR%\Temp\00ELStiSvc.TMP
- %APPDATA%\Microsoft\Network\mswmdm32.dll
- 'ne######ys.dyndns-blog.com':80
- 'ne######ys.dyndns-blog.com':443
- ne######ys.dyndns-blog.com/1/page_00271826.html
- DNS ASK ne######ys.dyndns-blog.com