Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\ssst] 'Start' = '00000002'
- '%TEMP%\AIS_2477_0.EXE'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- '<SYSTEM32>\rundll32.exe'
- %PROGRAM_FILES%\nnno\ddde.lex
- %PROGRAM_FILES%\nnno\tttu.dll
- %PROGRAM_FILES%\nnno\fffg.dll
- %PROGRAM_FILES%\nnno\rrrs.ini
- %PROGRAM_FILES%\nnno\qqqrlex\qqqrlex.ini
- %PROGRAM_FILES%\nnno\qqqr\qqqr.ini
- %PROGRAM_FILES%\nnno\iiij\iiij.ini
- %PROGRAM_FILES%\nnno\mmmn.ini
- %TEMP%\InsShell.exe
- %TEMP%\nsw2.tmp
- %PROGRAM_FILES%\nnno\xxxy.dll
- %PROGRAM_FILES%\nnno\cccd.dll
- %PROGRAM_FILES%\nnno\aaab.dll
- %PROGRAM_FILES%\nnno\iiij.ini
- %PROGRAM_FILES%\nnno\iiij.ini
- %TEMP%\AIS_2477_0.EXE
- C:\~de4.tmp
- C:\~de3.tmp
- %PROGRAM_FILES%\nnno\iiij.ini в C:\~de4.tmp
- %PROGRAM_FILES%\nnno\iiij\iiij.ini в %PROGRAM_FILES%\nnno\iiij.ini
- %TEMP%\InsShell.exe в %TEMP%\AIS_2477_0.EXE
- %TEMP%\AIS_2477_0.EXE в C:\~de3.tmp
- 'up####.borlander.cn':80
- up####.borlander.cn/upstdad5/userupdadlex.ini
- up####.borlander.cn/upiniad5/updadini.ini
- up####.borlander.cn/upstdad5/updstdii.ini
- DNS ASK ca#.###lander.com.cn
- DNS ASK www.bo####der.com.cn
- DNS ASK up####.borlander.cn
- ClassName: '_stdup_cha_wnd_' WindowName: '_stdup_cha_wnd_'
- ClassName: '_std_ad_wnd_' WindowName: '_std_ad_wnd_'