Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\dqqfrf] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\lnjvrk] 'Start' = '00000002'
- '%TEMP%\RarSFX0\lojk.exe'
- '<SYSTEM32>\sc.exe' stop lnjvrk
- '<SYSTEM32>\sc.exe' create dqqfrf type= kernel start= auto binpath= "%ALLUSERSPROFILE%\Application Data\KNTHZEE\dqqfrf.bin"
- '<SYSTEM32>\sc.exe' start lnjvrk
- '<SYSTEM32>\sc.exe' create lnjvrk type= kernel binpath= "%ALLUSERSPROFILE%\Application Data\KNTHZEE\lnjvrk.bin" start= auto
- '<SYSTEM32>\sc.exe' stop null
- %WINDIR%\Help\yx1341.hlp
- %WINDIR%\srchasst\yml9558
- %WINDIR%\Help\zl3239.hlp
- %WINDIR%\Temp\{a9396b64-0a6e-49f9-008a-7e1997e708c2}
- %ALLUSERSPROFILE%\Application Data\KNTHZEE\dqqfrf.bin
- %ALLUSERSPROFILE%\Application Data\KNTHZEE\hdn5588.nfo
- %TEMP%\RarSFX0\lojk.exe
- %TEMP%\1.tmp
- %WINDIR%\inf\nz4614.PNF
- %ALLUSERSPROFILE%\Application Data\KNTHZEE\lnjvrk.bin
- %TEMP%\1.tmp
- %ALLUSERSPROFILE%\Application Data\KNTHZEE\dqqfrf.bin
- %ALLUSERSPROFILE%\Application Data\KNTHZEE\lnjvrk.bin
- 'rp.##q88.com':80
- 'rp##.21civ.com':80
- rp.##q88.com/rp.php?om###################################################################################
- rp##.21civ.com/az.php?st######################################################
- DNS ASK www.ba##u.com
- DNS ASK rp.##q88.com
- DNS ASK rp##.21civ.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''