Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WinDC] 'Start' = '00000002'
- Средство контроля пользовательских учетных записей (UAC)
- <SYSTEM32>\svchqst.exe
- [<HKCU>\Software\Microsoft\Internet Explorer\Download] 'CheckExeSignatures' = 'no'
- %WINDIR%\Temp\aut2.tmp
- %WINDIR%\Temp\chdjxma
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\change[1].19&sys=WIN_XP
- %TEMP%\aut1.tmp
- %TEMP%\hsxlnwq
- <SYSTEM32>\svchqst.exe
- %WINDIR%\Temp\aut2.tmp
- %WINDIR%\Temp\chdjxma
- %TEMP%\aut1.tmp
- %TEMP%\hsxlnwq
- '2o#.#ytes.net':80
- 2o#.#ytes.net/change/?ap###############################
- DNS ASK 2o#.#ytes.net