Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Qq_Kk' = '<SYSTEM32>\wins\svchost.exe'
- <SYSTEM32>\wins\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\1[1].txt
- %TEMP%\23818.txt
- %TEMP%\28540.txt
- <SYSTEM32>\wins\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\1[1].txt
- 'tx#.#9com.org':80
- 'localhost':1036
- tx#.#9com.org/e/1.txt
- tx#.#9com.org/x/1.txt
- DNS ASK tx#.#9com.org