Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'shandian' = '%PROGRAM_FILES%\shandian\shandian.exe'
- %PROGRAM_FILES%\shandian\config.ini
- %PROGRAM_FILES%\shandian\Unins.exe
- %HOMEPATH%\Start Menu\Programs\ЙБµздЇААЖч\Р¶ФШ ЙБµздЇААЖч.lnk
- %HOMEPATH%\Desktop\ЙБµздЇААЖч.lnk
- %HOMEPATH%\Start Menu\Programs\ЙБµздЇААЖч\ЙБµздЇААЖч.lnk
- %TEMP%\nsk2.tmp\System.dll
- %TEMP%\nsk2.tmp\xID.dll
- %TEMP%\nsk2.tmp\Md5dll.dll
- %TEMP%\nsk2.tmp\open.ini
- %TEMP%\nsk2.tmp\NSISdl.dll
- %TEMP%\nsk2.tmp\System.dll
- %TEMP%\nsk2.tmp\xID.dll
- %TEMP%\nsk2.tmp\open.ini
- %TEMP%\nsk2.tmp\Md5dll.dll
- %TEMP%\nsk2.tmp\NSISdl.dll
- 'st##.#uashui.org':80
- st##.#uashui.org/stat/?v=########################################################################################
- DNS ASK st##.#uashui.org