Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Vpygjvhp] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k imgsvc
- '<SYSTEM32>\svchost.exe' -k netsvcs
- C:\WinTemp.ini
- %PROGRAM_FILES%\Google\Google.ocx
- %WINDIR%\WinQQ.dll
- C:\skin.jpg
- %WINDIR%\WinQQ.dll
- C:\skin.jpg
- C:\WinTemp.ini
- 'fm###8.3322.org':3313
- DNS ASK fm###8.3322.org