Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Service' = '%TEMP%\Microsoft_Install\services.exe'
- '%TEMP%\Microsoft_Install\services.exe'
- '<SYSTEM32>\wermgr.exe' -queuereporting
- '<SYSTEM32>\taskhost.exe' $(Arg0)
- C:\ProgramData\Microsoft\RAC\Temp\sql2368.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sql2348.tmp
- %TEMP%\Microsoft_Install\services.exe
- %TEMP%\Microsoft_Install\services.exe
- C:\ProgramData\Microsoft\RAC\Temp\sql2348.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sql2368.tmp
- 'he###.mjw.bz':80
- he###.mjw.bz/841484n.txt
- he###.mjw.bz/873355n.txt
- he###.mjw.bz/905305n.txt
- he###.mjw.bz/808958n.txt
- he###.mjw.bz/704282n.txt
- he###.mjw.bz/736480n.txt
- he###.mjw.bz/773499n.txt
- he###.mjw.bz/840470.asp
- he###.mjw.bz/872341.asp
- he###.mjw.bz/904275.asp
- he###.mjw.bz/807944.asp
- he###.mjw.bz/703268.asp
- he###.mjw.bz/735466.asp
- he###.mjw.bz/772267.asp
- DNS ASK he###.mjw.bz
- ClassName: 'Indicator' WindowName: ''