Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\lsass.exe
- '%HOMEPATH%\Start Menu\Programs\Startup\lsass.exe'
- <SYSTEM32>\cscript.exe
- %TEMP%\nsp4.tmp\System.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\s[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\s[1].htm
- %TEMP%\Jolanoyipek.dll
- %TEMP%\xacihozuvew.dll
- %TEMP%\nsg2.tmp\System.dll
- %TEMP%\Bijotebaz.dll
- %TEMP%\Sayazamu.uvu
- %TEMP%\nsp4.tmp\System.dll
- %TEMP%\Sayazamu.uvu
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\s[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\s[1].htm
- %TEMP%\Bijotebaz.dll
- %TEMP%\nsg2.tmp\System.dll
- %TEMP%\Jolanoyipek.dll
- %TEMP%\xacihozuvew.dll
- 'xy##1.su':80
- DNS ASK xy##1.su