Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Nopqhi Klmnopqr Tuv] 'Start' = '00000002'
- '%WINDIR%\atiecly.exe'
- 'C:\pb.exe'
- %WINDIR%\atiecly.exe
- C:\pb.exe
- C:\pb.exe
- '12#.0.1.4':8030
- 'www.ai###gji.com':8896
- 'ch####7.f3322.org':8030
- 'localhost':1036
- 'ch####7m.f3322.org':80
- ch####7m.f3322.org/mm.txt
- DNS ASK bu#.##gongji.com
- DNS ASK www.ai###gji.com
- DNS ASK ch####7m.f3322.org
- DNS ASK ch####7.f3322.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''