Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'suchost' = '%ProgramFiles%\Windows Portable Device\suchost.exe'
- %ProgramFiles%\windows portable device\suchost.exe
- %ProgramFiles%\windows portable device\unlockerhook.dll
- %ProgramFiles%\windows portable device\1.jc
- %ProgramFiles%\lydlq\lydlq.exe
- 'sf.##29sf.com':80
- http://sf.##29sf.com/2929.h
- DNS ASK sf.##29sf.com
- ClassName: '' WindowName: 'Microsoft Internet Explorer'
- ClassName: '' WindowName: ''
- '%ProgramFiles%\lydlq\lydlq.exe'