Техническая информация
- [<HKLM>\SYSTEM\ControlSet003\Services\xdwsao] 'start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\xdwsao] 'start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\xdwsao] 'Start' = '00000002'
- '%TEMP%\2.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %TEMP%\1.exb
- '<SYSTEM32>\svchost.exe' -k xdwsao
- '<SYSTEM32>\wscript.exe' "%TEMP%\3.vbs"
- %TEMP%\2.exe
- <SYSTEM32>\043a00.log
- <SYSTEM32>\yxoeof.dll
- %TEMP%\3.vbs
- %TEMP%\ql.bat
- %TEMP%\1.exb
- %TEMP%\2.exe
- 'sm####dgf.3322.org':80
- sm####dgf.3322.org/20130911/143530/465187.jsp
- sm####dgf.3322.org/20130911/143547/481781.jsp
- sm####dgf.3322.org/20130911/143457/432250.jsp
- sm####dgf.3322.org/20130911/143513/448421.jsp
- sm####dgf.3322.org/20130911/143638/533421.jsp
- sm####dgf.3322.org/20130911/143656/551187.jsp
- sm####dgf.3322.org/20130911/143604/498796.jsp
- sm####dgf.3322.org/20130911/143621/516218.jsp
- sm####dgf.3322.org/20130911/143317/331625.jsp
- sm####dgf.3322.org/20130911/143334/348859.jsp
- sm####dgf.3322.org/20130911/143244/299015.jsp
- sm####dgf.3322.org/20130911/143300/315312.jsp
- sm####dgf.3322.org/20130911/143425/399593.jsp
- sm####dgf.3322.org/20130911/143441/416156.jsp
- sm####dgf.3322.org/20130911/143351/366015.jsp
- sm####dgf.3322.org/20130911/143408/383437.jsp
- DNS ASK sm####dgf.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'