Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\VVYbfgjl] 'Start' = '00000002'
- '%CommonProgramFiles%\Microsoft Shared\MSInfo\NRVZfgko.exe'
- '%TEMP%\HELPCTR.EXE' -FromStartHelp
- '%TEMP%\360sd.exe'
- '%TEMP%\1.exe'
- '%TEMP%\2.exe'
- %TEMP%\HELPCTR.EXE
- %TEMP%\stinst.log
- <SYSTEM32>\5C440000.tmp
- %TEMP%\MSIMG32.dll
- %TEMP%\2.exe
- %TEMP%\1.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\NRVZfgko.exe
- %TEMP%\360sd.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\NRVZfgko.exe
- %TEMP%\HELPCTR.EXE
- %TEMP%\MSIMG32.dll
- 'hk####.no-ip.biz':7246
- 'cd#.##upload.com':80
- cd#.##upload.com/down/823401/360sd.jpg
- DNS ASK hk####.no-ip.biz
- DNS ASK .#.
- DNS ASK cd#.##upload.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'TAppBuilder' WindowName: '(null)'