Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WinIPCServ] 'Start' = '00000002'
- <SYSTEM32>\f165a.exe
- <SYSTEM32>\f165a.exe -s
- <SYSTEM32>\f165a.exe -i
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\9f1a.dll"
- <SYSTEM32>\rundll32.exe <SYSTEM32>\99a.dll,Always
- <SYSTEM32>\regsvr32.exe /u /s "<SYSTEM32>\5d11.dll"
- <SYSTEM32>\regsvr32.exe /u /s "<SYSTEM32>\9f1a.dll"
- %TEMP%\k5q6e\3.dll
- %TEMP%\k5q6e\2.dll
- %TEMP%\k5q6e\_uninstall
- %TEMP%\k5q6e\4.dll
- <SYSTEM32>\83-105-7163
- <SYSTEM32>\02afc
- <SYSTEM32>\9f1a.dll
- %TEMP%\k5q6e\b.dll.zgx
- %TEMP%\k5q6e\b.dll.zgx.tmp
- %TEMP%\k5q6e\setup.tmp
- %TEMP%\k5q6e\p.dll.zgx.tmp
- %TEMP%\k5q6e\s.exe
- %TEMP%\k5q6e\s.exe.tmp
- %TEMP%\k5q6e\p.dll.zgx
- %TEMP%\k5q6e\setup.tmp
- %TEMP%\k5q6e\_uninstall
- %TEMP%\k5q6e\s.exe.tmp
- %TEMP%\k5q6e\b.dll.zgx.tmp
- %TEMP%\k5q6e\p.dll.zgx.tmp
- %TEMP%\k5q6e\3.dll в %WINDIR%\b45a.exe
- %TEMP%\k5q6e\b.dll в <SYSTEM32>\9f1a.dll
- %TEMP%\k5q6e\4.dll в %WINDIR%\45d1a.txt
- %TEMP%\k5q6e\s.exe в <SYSTEM32>\f165a.exe
- %TEMP%\k5q6e\p.dll.zgx в %TEMP%\k5q6e\p.dll
- %TEMP%\k5q6e\b.dll.zgx в %TEMP%\k5q6e\b.dll
- %TEMP%\k5q6e\2.dll в %WINDIR%\2ba.bmp
- %TEMP%\k5q6e\p.dll в <SYSTEM32>\99a.dll
- '88#.#43call.cn':80
- '12#.##0304123.cn':80
- DNS ASK 88#.#43call.cn
- DNS ASK 12#.##0304123.cn
- DNS ASK ya###.com.cn