Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\ias] 'Start' = '00000002'
- C:\Inpaint.exe
- C:\youyou.exe
- %TEMP%\120468.txt
- <SYSTEM32>\bhoiqdespy
- <Текущая директория>\qxvmttvqlc
- C:\youyou.exe
- C:\Inpaint.exe
- <SYSTEM32>\config\SysEvent.Evt
- C:\youyou.exe
- <SYSTEM32>\bhoiqdespy
- <Текущая директория>\qxvmttvqlc
- <SYSTEM32>\config\AppEvent.Evt
- <SYSTEM32>\config\SecEvent.Evt
- %TEMP%\120468.txt в %PROGRAM_FILES%\Google\idx.dll
- 'qq####ou.gicp.net':6587
- 'qq####ou.3322.org':8312
- DNS ASK qq####ou.gicp.net
- DNS ASK qq####ou.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: ''