Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\start.lnk
- '%WINDIR%\svchost.exe'
- '%WINDIR%\svchost.exe' (загружен из сети Интернет)
- '<SYSTEM32>\rundll32.exe' %WINDIR%\temp\cmss.dat hi
- %WINDIR%\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\httpd[1].exe
- %WINDIR%\Temp\cmss.dat
- 'wb####09.3322.org':80
- '11###3.3322.org':8000
- wb####09.3322.org/httpd.exe
- DNS ASK wb####09.3322.org
- DNS ASK 11###3.3322.org