Техническая информация
- '<SYSTEM32>\rundll32.exe' YNGRE8.dll,load S4uClsM.dll
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\S4uClsM.dll
- %TEMP%\Version.txt
- <SYSTEM32>\YNGRE8.dll
- <SYSTEM32>\NnY6P6.dll
- <SYSTEM32>\pmonitor.tmp
- <SYSTEM32>\pmonitor.tmp
- %TEMP%\Version.txt
- '<IP-адрес в локальной сети>':53
- 'cl###.rtmedia.cn':80
- '12#.#25.114.144':80
- 'cn##n.com':80
- 'www.ba###bar.info':80
- cn##n.com/6lV4
- 12#.#25.114.144/ecom?di##################################################################
- cl###.rtmedia.cn/d.aspx
- cn##n.com/aEi4
- www.ba###bar.info/rtbho.xml
- cn##n.com/pTg4
- DNS ASK cl###.rtmedia.cn
- DNS ASK cb.##idu.com
- DNS ASK cn##n.com
- DNS ASK www.ba###bar.info
- '25#.#55.255.255':32336
- ClassName: 'Progman' WindowName: 'Program Manager'