Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\AppMgmt] 'Start' = '00000002'
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\services\AppMgmt\Parameters" /v ServiceDll /t REG_EXPAND_SZ /d "<SYSTEM32>\wbem\cimmapp.dll" /f
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\C4BC81SE\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S10VSR45\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XSQFRBLV\desktop.ini
- <SYSTEM32>\wbem\cimmapp.dll
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\DI6JHWTY\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S10VSR45\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XSQFRBLV\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\DI6JHWTY\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\C4BC81SE\desktop.ini
- 'us##.#zone.qq.com':80
- us##.#zone.qq.com/184920419
- DNS ASK us##.#zone.qq.com