Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\AppMgmt] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\bFVgTfYPK] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\pwdUNeWNvB] 'Start' = '00000002'
- <SYSTEM32>\appmgmts.dll
- <SYSTEM32>\bFVgTfYPK.sys
- %WINDIR%\Temp\37264126.tmp
- %WINDIR%\Temp\36AF1D11.tmp
- C:\Documents and Settings\Infortmp.txt
- <SYSTEM32>\54220594.tmp
- <SYSTEM32>\pwdUNeWNvB.sys
- %WINDIR%\Temp\37264126.tmp
- %WINDIR%\Temp\36AF1D11.tmp
- <SYSTEM32>\pwdUNeWNvB.sys
- C:\Documents and Settings\Infortmp.txt
- <SYSTEM32>\54220594.tmp
- 'go.###i8765ds.info':799
- '10#.#4.183.47':799
- '11#.#38.237.83':799
- 'p.###456.com':75
- 'ts.##ss520.com':799
- DNS ASK ts.##ss520.com
- DNS ASK go.###i8765ds.info
- DNS ASK www.ba##u.com
- DNS ASK p.###456.com