Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\ERSvc] 'Start' = '00000002'
- <SYSTEM32>\ersvc.dll
- <SYSTEM32>\dllcache\ersvc.dll файлом <SYSTEM32>\dllcache\ersvc.dll.new
- <SYSTEM32>\ersvc.dll файлом <SYSTEM32>\ersvc.dll.new
- <SYSTEM32>\svchost.exe -k netsvcs
- %TEMP%\suareew.dll
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\Config[1].txt
- %WINDIR%\KB956391_ie.log
- <SYSTEM32>\KB936782.dll.bak
- <SYSTEM32>\ersvc.dll.tmp
- <SYSTEM32>\dllcache\ersvc.dll.new в <SYSTEM32>\dllcache\ersvc.dll
- <SYSTEM32>\ersvc.dll в <SYSTEM32>\ersvc.dll.tmp
- 'www.ji###123.com':80
- 'localhost':1035
- www.ji###123.com/002/Count.asp?ma#######################################
- www.ji###123.com/Config.txt
- DNS ASK www.ji###123.com