Техническая информация
- [HKLM\System\CurrentControlSet\Services\jjDIS] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\jjDIS] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- 'jjDIS' <SYSTEM32>\svchost.exe -k netsvcs
- 'tunnel' system32\DRIVERS\tunnel.sys
- %TEMP%\ixp000.tmp\1.exe
- %TEMP%\ixp000.tmp\games.exe
- C:\newbook
- %WINDIR%\plugin_info.ini
- %ProgramFiles(x86)%\djja.dll
- %TEMP%\ixp000.tmp\1.exe
- DNS ASK uc####001.gicp.net
- '%TEMP%\ixp000.tmp\1.exe'
- '%TEMP%\ixp000.tmp\games.exe'
- '%WINDIR%\syswow64\cmd.exe' /c del %TEMP%\IXP000.TMP\1.exe (со скрытым окном)