Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Please Input Service Name] 'Start' = '00000002'
- <Текущая директория>\Delete.exe
- C:\БѕЗХёЕЕ©·О[1АОАЪ].exe
- C:\ЅЗЗаЗПёй ЅГАЫ.exe
- <SYSTEM32>\svchost.exe -k imgsvc
- <SYSTEM32>\svchost.exe -k netsvcs
- C:\Net-Temp.ini
- C:\NT_Path.old
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\patcher.xe[1]
- %WINDIR%\FileName.jpg
- %WINDIR%\temp2983500.dll
- C:\БѕЗХёЕЕ©·О[1АОАЪ].exe
- C:\ЅЗЗаЗПёй ЅГАЫ.exe
- <Текущая директория>\Delete.exe
- <Текущая директория>\123.txt
- C:\ЅЗЗаЗПёй ЅГАЫ.exe
- %WINDIR%\temp2983500.dll
- C:\NT_Path.old
- <Текущая директория>\123.txt
- C:\Net-Temp.ini
- 'pa###er.xe.to':80
- 'sd####4.codns.com':8080
- 'wi####.dothome.co.kr':80
- 'localhost':1038
- pa###er.xe.to/
- wi####.dothome.co.kr/bbs/view.php?id########################################################################################################################
- DNS ASK sd####4.codns.com
- DNS ASK pa###er.xe.to
- DNS ASK wi####.dothome.co.kr
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'AutoHotkey' WindowName: 'C:\??????????[1????].exe'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'AutoHotkey' WindowName: '<Текущая директория>\Delete.exe'