Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\ias] 'Start' = '00000002'
- <SYSTEM32>\rundll32.exe %ALLUSERSPROFILE%\drm\uxdjr.dll,DllCanUnloadNow 1148
- %TEMP%\209468.log
- <SYSTEM32>\config\SysEvent.Evt
- <SYSTEM32>\config\SecEvent.Evt
- <SYSTEM32>\config\AppEvent.Evt
- %TEMP%\209468.log в %ALLUSERSPROFILE%\DRM\uxdjr.dll
- 'ju##.vicp.net':5302
- 'ju##.8800.org':5302
- 'sd###q.vicp.net':5302
- 'sd###q.3322.org':5302
- DNS ASK ju##.vicp.net
- DNS ASK ju##.8800.org
- DNS ASK sd###q.vicp.net
- DNS ASK sd###q.3322.org