Техническая информация
- [HKLM\System\CurrentControlSet\Services\kr76NeN77P] 'ImagePath' = '<SYSTEM32>\kr76NeN77P.sys'
- 'kr76NeN77P' <SYSTEM32>\kr76NeN77P.sys
- <Текущая директория>\dfload.exe
- <SYSTEM32>\kr76nen77p.sys
- %WINDIR%\temp\udd9d96.tmp
- <Текущая директория>\kss.ini
- %WINDIR%\temp\udda573.tmp
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %WINDIR%\temp\uddad51.tmp
- %WINDIR%\temp\uddb51e.tmp
- %WINDIR%\temp\uddbcec.tmp
- %WINDIR%\temp\uddc4ca.tmp
- <Текущая директория>\dfload.exe
- %WINDIR%\temp\udd9d96.tmp
- %WINDIR%\temp\udda573.tmp
- %WINDIR%\temp\uddad51.tmp
- %WINDIR%\temp\uddb51e.tmp
- %WINDIR%\temp\uddbcec.tmp
- %WINDIR%\temp\uddc4ca.tmp
- 'da###ngwg.com':80
- http://www.da###ngwg.com/config.txt
- DNS ASK da###ngwg.com
- DNS ASK da####g.886fz.com
- DNS ASK ws#####.gfhost.supidc.net
- DNS ASK pi###ifz.com
- DNS ASK fk.###fengwg.com
- DNS ASK fk#.##ofengwg.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<Текущая директория>\dfload.exe'