Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\services\Kxwtvr Cpyblk] 'Start' = '00000002'
- '<SYSTEM32>\rundll32.exe' "%PROGRAM_FILES%\Internet Explorer\termial.dll", dkjfdkfjdkjfdkfjd
- '<SYSTEM32>\svchost.exe' -k imgsvc
- C:\NetTemp.ini
- %PROGRAM_FILES%\Internet Explorer\termial.dll
- C:\map1290500.dll
- C:\heygirl.ddd
- C:\map1290500.dll
- C:\heygirl.ddd
- C:\NetTemp.ini
- 'ss####5.codns.com':3771
- DNS ASK dn#.##ftncsi.com
- DNS ASK ss####5.codns.com