Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = '<SYSTEM32>\winimm32.exe'
- %WINDIR%\Tasks\ahnsvr.dat
- %WINDIR%\Tasks\ntfsny.dat
- %WINDIR%\Tasks\midisappe.dat
- [<HKLM>\SYSTEM\ControlSet001\Services\ntfsny] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\ahnsvr] 'Start' = '00000002'
- %WINDIR%\Explorer.EXE
- NtQuerySystemInformation, драйвер-обработчик: unknown
- NtSetInformationFile, драйвер-обработчик: unknown
- NtQueryDirectoryFile, драйвер-обработчик: unknown
- NtEnumerateKey, драйвер-обработчик: unknown
- NtEnumerateValueKey, драйвер-обработчик: unknown
- %WINDIR%\ver.dat
- %WINDIR%\wallball.dat
- <DRIVERS>\ahnsvr.sys
- <SYSTEM32>\midisappe.dll
- <DRIVERS>\ntfsny.sys
- <DRIVERS>\ahnsvr.sys
- <SYSTEM32>\midisappe.dll
- %WINDIR%\Tasks\midisappe.dat
- <DRIVERS>\ntfsny.sys
- 'www.ne##v.com':80
- www.ne##v.com/d21/board.asp
- DNS ASK www.ne##v.com
- ClassName: 'VcSpiderClass' WindowName: 'VcSpiderClass'