Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\HidServ] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\AudioSrv] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\.Net CLR] 'Start' = '00000002'
- %PROGRAM_FILES%\hgdtykvodp a -s%CommonProgramFiles%\C34F30EA.exe
- %CommonProgramFiles%\B2F52F77.exe
- %CommonProgramFiles%\C34F30EA.exe
- <SYSTEM32>\svchost.exe -k ".Net CLR"
- %TEMP%\qbxtfvsicf.dat
- %CommonProgramFiles%\nintwvqyq
- %CommonProgramFiles%\lfcopobms
- %CommonProgramFiles%\nintwvqyqs
- %CommonProgramFiles%\C34F30EA.exe
- %CommonProgramFiles%\B2F52F77.exe
- <SYSTEM32>\360sd.dll
- %PROGRAM_FILES%\hgdtykvodp
- %CommonProgramFiles%\nintwvqyqs
- %CommonProgramFiles%\lfcopobms
- %CommonProgramFiles%\B2F52F77.exe
- %CommonProgramFiles%\C34F30EA.exe
- %CommonProgramFiles%\nintwvqyq
- %TEMP%\qbxtfvsicf.dat в %ALLUSERSPROFILE%\Application Data\Storm\update\%windowsname%\jiqxm.jpg
- %PROGRAM_FILES%\hgdtykvodp в %PROGRAM_FILES%\hgd
- 'jw###.3322.org':8181
- DNS ASK jw###.3322.org