Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Server] 'Start' = '00000002'
- '%CommonProgramFiles%\Microsoft Shared\MSInfo\rejoice08.exe'
- '<SYSTEM32>\cmd.exe' /c "%CommonProgramFiles%\Microsoft Shared\MSINFO\DaverDel.bat"
- %CommonProgramFiles%\Microsoft Shared\MSInfo\DaverDel.bat
- %WINDIR%\SetupWay.TXT
- %CommonProgramFiles%\Microsoft Shared\MSInfo\rejoice08.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\rejoice08.exe
- 'aq####ng.3322.org':8181
- DNS ASK aq####ng.3322.org