Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'nplog2' = 'rundll32 %APPDATA%\nplog.log,rdl'
- '%APPDATA%\tutu_A.exe'
- '<SYSTEM32>\rundll32.exe' %APPDATA%\nplog.log,rdl
- %WINDIR%\aution.ico
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\aution[1].ico
- %HOMEPATH%\Favorites\їБјЗ.url
- %HOMEPATH%\Desktop\їБјЗ.url
- %APPDATA%\nplog.log
- %TEMP%\aut1.tmp
- %APPDATA%\tutu_A.exe
- %TEMP%\aut2.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\aution[1].ico
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- 'ba####.funtvi.kr':80
- 'md###.funtvi.kr':80
- 'localhost':1035
- ba####.funtvi.kr/action.php?pa######################
- md###.funtvi.kr/bacon/aution.ico
- DNS ASK ba####.funtvi.kr
- DNS ASK md###.funtvi.kr
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'