Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\LoadGroup] 'Start' = '00000002'
- <SYSTEM32>\EITHEWUGVLXNI.EXE
- <SYSTEM32>\EITHEWUGVLXNI.EXE /install /silent
- <SYSTEM32>\net1.exe start LoadGroup
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\VLHJYPXFJOYZ.DLL"
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\TXQHGSRH.DLL
- <SYSTEM32>\IMQSU.DLL
- <SYSTEM32>\EITHEWUGVLXNI.EXE
- <SYSTEM32>\YHJUWSERWNXG.AET
- <SYSTEM32>\ZMMFNDEAZAXYDEX.OKC
- <DRIVERS>\IBCOWTLBXMMBW.DAT
- <SYSTEM32>\8u1mk8w7.dll
- <SYSTEM32>\EMZSJDPRNBGA.INI
- <SYSTEM32>\wbem\CIHVIUZZQXZN.DLL
- <SYSTEM32>\VLHJYPXFJOYZ.DLL
- <SYSTEM32>\TXQHGSRH.exe в <SYSTEM32>\TXQHGSRH.DLL
- <SYSTEM32>\TXQHGSRH.DLL в <SYSTEM32>\TXQHGSRH.exe
- 'ad.##kead.com':80
- 'www.mo##ad.com':80
- 'fz##.com':80
- ad.##kead.com/starts.asp?id######################
- www.mo##ad.com/config/Info.txt
- fz##.com/
- DNS ASK ad.##kead.com
- DNS ASK www.mo##ad.com
- DNS ASK fz##.com
- ClassName: 'MS_WINHELP' WindowName: ''