Техническая информация
- '<SYSTEM32>\rundll32.exe' sOi4Oj4.dll,load YWwEJqO1.dll
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\sOi4Oj4.dll
- <SYSTEM32>\YWwEJqO1.dll
- %TEMP%\Version.txt
- <SYSTEM32>\RtSessionID.dll
- <SYSTEM32>\PqmLNhO.dll
- <SYSTEM32>\pmonitor.tmp
- <SYSTEM32>\pmonitor.tmp
- %TEMP%\Version.txt
- '12#.#25.114.144':80
- 'cl###.rtmedia.cn':80
- '<IP-адрес в локальной сети>':53
- 'cn##n.com':80
- 'ba###bar.info':80
- 12#.#25.114.144/ecom?di##################################################################
- cn##n.com/6kg8
- cl###.rtmedia.cn/d.aspx
- cn##n.com/6lV4
- cn##n.com/5nc5
- ba###bar.info/rtbho.xml
- cn##n.com/pTg4
- DNS ASK cl###.rtmedia.cn
- DNS ASK cb.##idu.com
- DNS ASK cn##n.com
- DNS ASK ba###bar.info
- '25#.#55.255.255':32336
- ClassName: 'Progman' WindowName: 'Program Manager'