Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\AppMgmt] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\klan] 'Start' = '00000002'
- <SYSTEM32>\appmgmts.dll
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\TempDel.bat" "
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\P4YW5D0A\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IYC31JVK\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OP804WFJ\ggb[1].txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\W9UFG5YB\desktop.ini
- %TEMP%\TempDel.bat
- %TEMP%\BuilLog.txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OP804WFJ\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\P4YW5D0A\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\W9UFG5YB\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OP804WFJ\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IYC31JVK\desktop.ini
- %TEMP%\BuilLog.txt в <DRIVERS>\klan.sys
- 'tt.##88567.cn':80
- 'localhost':1035
- tt.##88567.cn/bbs/ggb.txt
- DNS ASK tt.##88567.cn