Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Control\Lsa] 'Notification Packages' = ''
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Monitors\SCSI Port Monitor] 'Driver' = 'scsimon.dll'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WmLogon] 'Startup' = 'Startup'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WmLogon] 'DllName' = 'WmLogon.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler] 'Start' = '00000002'
- <SYSTEM32>\rundll32.exe "%WINDIR%\temp\206640.dll" DllService
- <SYSTEM32>\svchost.exe -k ProcInHost:spoolsv:Memory
- <SYSTEM32>\spoolsv.exe
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\WmLogon.dll
- <SYSTEM32>\wbem\WmLogon.dll
- <SYSTEM32>\lsascur.dll
- <SYSTEM32>\scsimon.dll
- <SYSTEM32>\wbem\scsimon.dll
- C:\wmpub\wmiislog\AcSvcst.dll
- %WINDIR%\Temp\206640.dll
- <SYSTEM32>\Com\pdrv.dll
- <SYSTEM32>\Com\comb.dll
- C:\wmpub\wmiislog\AvcAlvr.dll
- <SYSTEM32>\scanreg.exe
- <SYSTEM32>\wbem\scsimon.dll
- 'rs#.##one.qq.com':80
- rs#.##one.qq.com/cgi-bin/feeds/feeds_html_module?i_##########
- DNS ASK rs#.##one.qq.com