Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'odby' = '%WINDIR%\odb.exe'
- %WINDIR%\odb.exe
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- 'sa###ngins.cn':80
- http://sa###ngins.cn/nop/tds2.php
- DNS ASK sa###ngins.cn
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''