Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\AFW] 'ImagePath' = '%TEMP%\001191b4.sys'
- 'AFW' %TEMP%\001191b4.sys
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\tmp118e69.exe
- %TEMP%\nsr9176.tmp
- %TEMP%\mydnsapi.dll
- %TEMP%\001191b4
- %TEMP%\whenu.ini
- %TEMP%\banner.bmp
- %TEMP%\nsw9232.tmp\iospecial.ini
- %TEMP%\nsw9232.tmp\modern-wizard.bmp
- %TEMP%\nsw9232.tmp\modern-header.bmp
- %TEMP%\nsw9232.tmp\installoptions.dll
- %WINDIR%\temp\udd95c9.tmp
- %WINDIR%\temp\udd95c9.tmp
- %TEMP%\001191b4 в %TEMP%\001191b4.sys
- DNS ASK windowsupdate.com
- DNS ASK google.com
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' -nohome
- '%WINDIR%\syswow64\svchost.exe'