Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\iCount] 'Start' = '00000002'
- '%APPDATA%\535.exe'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %WINDIR%\Temp\iCount.ini
- %WINDIR%\Temp\WinService.dll
- %APPDATA%\535.exe
- %WINDIR%\Temp\iCount.ini
- %WINDIR%\Temp\WinService.dll
- %APPDATA%\535.exe
- %APPDATA%\535.exe
- 'www.dn##090.com':80
- '59##lay.com':80
- www.dn##090.com/yc.jpg
- 59##lay.com/gg.txt
- DNS ASK www.dn##090.com
- DNS ASK 59##lay.com