Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'New Bot Test' = '%ALLUSERSPROFILE%\Dxnlcm1.exe'
- %ALLUSERSPROFILE%\dxnlcm1.exe
- %ALLUSERSPROFILE%\chkdos.dll
- %ALLUSERSPROFILE%\insomnia.dll
- 'localhost':80
- DNS ASK ap#.##pmania.com
- DNS ASK ir#.#ackt.org
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- '%ALLUSERSPROFILE%\dxnlcm1.exe'
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\dw20.exe' -x -s 1148