Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Sysudp' = '<SYSTEM32>\config\sysudp.exe'
- <SYSTEM32>\wscript.exe "c:\y.vbs"
- <SYSTEM32>\Com\sysrp.rar
- <SYSTEM32>\config\sysudp.rmd
- <SYSTEM32>\Com\sysrp.tmp
- C:\sys.dll
- C:\y.vbs
- C:\y.vbs
- 'pr#.###umyardimcim.com':445
- 'pr#.###umyardimcim.com':1433
- DNS ASK pr#.###umyardimcim.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''