Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\irmon] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Ias] 'Start' = '00000002'
- 'C:\setup_03-14.exe'
- 'C:\Лў№·Бёbug.exe'
- 'C:\Server.exe'
- '<SYSTEM32>\notepad.exe' C:\Лў№·Бёbug.txt
- '<SYSTEM32>\svchost.exe' -k neTsvcs
- <SYSTEM32>\itzoxm
- <Текущая директория>\Ias
- <Текущая директория>\lnmtoldujx
- <SYSTEM32>\ujabbctuun
- %TEMP%\lpmnfpoyuh.log
- C:\Лў№·Бёbug.exe
- C:\Server.exe
- %TEMP%\lbgnlkap.tmp
- C:\setup_03-14.exe
- C:\Лў№·Бёbug.txt
- <SYSTEM32>\ujabbctuun
- <SYSTEM32>\config\SecEvent.Evt
- C:\setup_03-14.exe
- <SYSTEM32>\config\SysEvent.Evt
- C:\Server.exe
- <Текущая директория>\Ias
- <SYSTEM32>\config\AppEvent.Evt
- <Текущая директория>\lnmtoldujx
- %TEMP%\lpmnfpoyuh.log в %PROGRAM_FILES%\NetMeeting\knfew.lib
- %TEMP%\lbgnlkap.tmp в %PROGRAM_FILES%\Internet Explorer\dyfsv.exe
- 'mc###8.3322.org':308
- 'qw##.3322.org':8000
- DNS ASK mc###8.3322.org
- DNS ASK qw##.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: ''