Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\NtmsSvc] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Ipv6to4] 'Start' = '00000001'
- <SYSTEM32>\dllcache\beep.sys файлом <SYSTEM32>\dllcache\beep.sys.new
- <DRIVERS>\beep.sys файлом <DRIVERS>\beep.sys.new
- <DRIVERS>\beep.sys файлом <DRIVERS>\Beep.sys
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\_uninsep1.bat" "
- <SYSTEM32>\svchost.exe
- %TEMP%\_uninsep1.bat
- <SYSTEM32>\ntmssrv.dll
- <DRIVERS>\ipv6to4.sys
- <SYSTEM32>\ntmssrv.dll
- <DRIVERS>\ipv6to4.sys
- <DRIVERS>\beep.sys
- <SYSTEM32>\dllcache\beep.sys.new в <SYSTEM32>\dllcache\beep.sys
- 'wo###.esmtp.biz':443
- 'mu###.port25.biz':443
- DNS ASK wo###.eSMTP.biz
- DNS ASK mu###.port25.biz