Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\duotes] 'Start' = '00000002'
- <SYSTEM32>\svchost.exe -k netsvcs
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\xiong[1].txt
- %WINDIR%\duote.dll
- <Текущая директория>\KKK.dll
- %WINDIR%\duote.dll.uns
- %WINDIR%\duote.dll
- <Текущая директория>\KKK.dll
- 'my###r.ggxx.cc':80
- my###r.ggxx.cc/xiong.txt
- DNS ASK my###r.ggxx.cc
- ClassName: 'Afx:400000:0' WindowName: ''