Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\DCE] 'Start' = '00000002'
- '%PROGRAM_FILES%\DCE\dce.exe'
- '%TEMP%\nsa3.tmp\ns5.tmp' cmd /C ""<SYSTEM32>\sc.exe" create DCE start= auto displayname= "Distributed Computing Experiment" binPath= "%PROGRAM_FILES%\DCE\dce.exe""
- '<SYSTEM32>\sc.exe' start DCE
- '<SYSTEM32>\sc.exe' create DCE start= auto displayname= "Distributed Computing Experiment" binPath= "%PROGRAM_FILES%\DCE\dce.exe"
- '<SYSTEM32>\sc.exe' delete DCE
- %TEMP%\nsa3.tmp\nsExec.dll
- %TEMP%\nsa3.tmp\ns5.tmp
- %PROGRAM_FILES%\DCE\uninst.exe
- %PROGRAM_FILES%\DCE\dce.exe
- %TEMP%\nsp2.tmp
- %TEMP%\DCE\DCELog.log
- %TEMP%\nsa3.tmp\System.dll
- %TEMP%\nsa3.tmp\System.dll
- %TEMP%\nsa3.tmp\nsExec.dll
- %TEMP%\nsa3.tmp\ns5.tmp
- 'dc#.###ffic-offers.com':80
- dc#.###ffic-offers.com/dce.ashx?ui###########################################
- dc#.###ffic-offers.com/p.ashx?ui###########################################
- DNS ASK dc#.###ffic-offers.com