Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\d0a18r] 'ImagePath' = '<DRIVERS>\d0a18r.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\d0a18r] 'ImagePath' = 'System32\DRIVERS\d0a18r.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\d0a18r] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\dat4c] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\dat4c] 'ImagePath' = '<DRIVERS>\dat4c.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\d0a18r] 'Start' = '00000002'
- <DRIVERS>\d0a18r.sys
- <SYSTEM32>\loi9q.dll
- %HOMEPATH%\Favorites\КХІШ.url
- <DRIVERS>\dat4c.sys
- 'tm#.#arfly.org':80
- http://tm#.#arfly.org/rpt103p60000
- http://tm#.#arfly.org/rpt5p60000
- DNS ASK tm#.#arfly.org