Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = 'c:\apicgysry\start.lnk'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\start.lnk
- 'C:\apicgysry\csrss.exe' "c:\apicgysry\mydat.dll",InitSkin
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\plus[1].php
- C:\apicgysry\data.mdb
- C:\apicgysry\start.lnk
- C:\apicgysry\mydat.dll
- C:\apicgysry\csrss.exe
- <DRIVERS>\etc\hosts
- C:\apicgysry\data.mdb
- 'qe##f.com':8088
- 'any':8088
- 'qe##f.com':80
- qe##f.com/plus.php
- DNS ASK qq#.#esff.com
- DNS ASK qe##f.com