Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\W32Time] 'Start' = '00000002'
- 'C:\DNF№¤ѕЯґуИ«ЧФ¶ЇКХ»х °ЪМЇ Л«їЄ Б¬·ўЎ¤Ў¤Ў¤Ў¤Ў¤Ў¤.exe'
- 'C:\server.exe'
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://bb#.#996.com/
- %PROGRAM_FILES%\NVIDIA\XOPntEx.Dll
- %PROGRAM_FILES%\NVIDIA\NVIDIA.OLE
- C:\server.exe
- C:\DNF№¤ѕЯґуИ«ЧФ¶ЇКХ»х °ЪМЇ Л«їЄ Б¬·ўЎ¤Ў¤Ў¤Ў¤Ў¤Ў¤.exe
- C:\DNF№¤ѕЯґуИ«ЧФ¶ЇКХ»х °ЪМЇ Л«їЄ Б¬·ўЎ¤Ў¤Ў¤Ў¤Ў¤Ў¤.exe
- C:\server.exe
- C:\server.exe в %TEMP%\SJ.html
- 'bb#.#996.com':80
- 'xq#####3538.gicp.net':6380
- 'localhost':1038
- bb#.#996.com/
- DNS ASK bb#.#996.com
- DNS ASK xq#####3538.gicp.net
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: 'opjkropioiasdjaieee'
- ClassName: 'Shell_TrayWnd' WindowName: ''