Техническая информация
- %WINDIR%\Tasks\AAQZYQ.job
- '<SYSTEM32>\rsopg.exe' "<SYSTEM32>\rsopg.exe",Htfqyq
- '<SYSTEM32>\ipconfig.exe' /flushdns
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\K9R0ZZT4\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6PM9STUD\desktop.ini
- %TEMP%\~unins296.bat
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KLYJOL23\desktop.ini
- <SYSTEM32>\rsopg.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XNDNZMPQ\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KLYJOL23\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\K9R0ZZT4\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6PM9STUD\desktop.ini
- %WINDIR%\Tasks\AAQZYQ.job
- <SYSTEM32>\rsopg.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XNDNZMPQ\desktop.ini
- <SYSTEM32>\Restore\MachineGuid.txt
- 'im###hut4.cn':80
- 'wi###ounter.net':80
- im###hut4.cn/update/utu.dat
- DNS ASK im###hut4.cn
- DNS ASK wi###ounter.net