Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\nznaio] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\nznaio] 'ImagePath' = '<SYSTEM32>\svchost.exe -k nznaio'
- [<HKLM>\SYSTEM\ControlSet001\Services\nznaio\Parameters] 'ServiceDll' = '%CommonProgramFiles%\Microsoft Shared\VC\nznaio.dll'
- [<HKLM>\SYSTEM\ControlSet002\Services\nznaio\Parameters] 'ServiceDll' = '%CommonProgramFiles%\Microsoft Shared\VC\nznaio.dll'
- [<HKLM>\SYSTEM\ControlSet002\Services\nznaio] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet003\Services\nznaio\Parameters] 'ServiceDll' = '%CommonProgramFiles%\Microsoft Shared\VC\nznaio.dll'
- [<HKLM>\SYSTEM\ControlSet003\Services\nznaio] 'Start' = '00000002'
- %TEMP%\buxie.exe
- %TEMP%\ЦЗБЄХРЖё_МЖґНМґ_ЗуЦ°_ІЖОсКµП°Йъ(±ПТµЙъ).doc
- %TEMP%\_138796__2.tmp
- %TEMP%\_138796__.tmp
- %TEMP%\142359.bat
- %TEMP%\_138796__2.tmp
- %TEMP%\buxie.exe
- %TEMP%\_138796__.tmp в %CommonProgramFiles%\Microsoft Shared\VC\nznaio.dll
- 'ns#.##kiadns.com':80
- DNS ASK ns#.##kiadns.com
- ClassName: 'WordPadClass' WindowName: ''
- '%TEMP%\buxie.exe'
- '%ProgramFiles%\Windows NT\Accessories\wordpad.exe' "%TEMP%\ЦЗБЄХРЖё_МЖґНМґ_ЗуЦ°_ІЖОсКµП°Йъ(±ПТµЙъ).doc"
- '<SYSTEM32>\rundll32.exe' "%CommonProgramFiles%\Microsoft Shared\VC\nznaio.dll",Install
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\142359.bat" "%TEMP%\""
- '<SYSTEM32>\svchost.exe' -k nznaio
- '<SYSTEM32>\attrib.exe' -r -s -h"%TEMP%\"