Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\aspnet_states] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\DSLserverorm] 'Start' = '00000002'
- '%TEMP%\100.exe'
- '<SYSTEM32>\aaaaaa.exe'
- '%TEMP%\vip.exe'
- '<SYSTEM32>\qqeuqi.exe'
- <SYSTEM32>\qqeuqi.exe
- <SYSTEM32>\aaaaaa.exe
- %TEMP%\vip.exe
- %TEMP%\100.exe
- %TEMP%\100.exe в %TEMP%\SOFTWARE.LOG
- 'co####.api.css361.com':80
- 'ge###.api520.com':1001
- 'cc.##i520.com':1002
- co####.api.css361.com/baohe/wb/update.txt
- DNS ASK co####.api.css361.com
- DNS ASK ge###.api520.com
- DNS ASK cc.##i520.com
- ClassName: 'Shell_TrayWnd' WindowName: ''