Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\IPRIP] 'Start' = '00000002'
- <SYSTEM32>\rundll32.exe shell32.dll,#115HelloWorld "%TEMP%\..\17DA7.dll"
- <SYSTEM32>\1149\AVCheck
- %HOMEPATH%\Local Settings\17DA7.dll
- %ALLUSERSPROFILE%\DDRatUp
- 'li####28.gicp.net':53
- DNS ASK li####28.gicp.net
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''