Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{24D49C0F-8257-6F99-AF75-14B630E4D602}] 'stubpath' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\NdisFileServices32] 'Start' = '00000002'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\Bifrost\Server.exe
- <DRIVERS>\fkgljn.sys
- <SYSTEM32>\wmdrtc32.dl_
- <SYSTEM32>\wmdrtc32.dll
- <DRIVERS>\fkgljn.sys
- 'www.lu####dnd2kdnc.info':80
- 'www.f5####kkk4d.info':80
- 'www.hk####123ncs.info':80
- 'www.h7#####1wlsdn34fgv.info':80
- 'www.bp##02.com':80
- 'ma#####oda.no-ip.biz':200
- 'www.g1#####vns3sdsal.info':80
- 'www.in####1ongung.info':80
- www.lu####dnd2kdnc.info/t_100_v400/?rn#######################
- www.h7#####1wlsdn34fgv.info/t_100_v400/?rn#######################
- www.hk####123ncs.info/t_100_v400/?rn#######################
- www.f5####kkk4d.info/t_100_v400/?rn#######################
- www.bp##02.com/t_100_v400/?rn#######################
- www.in####1ongung.info/t_100_v400/?rn#######################
- www.g1#####vns3sdsal.info/t_100_v400/?rn#######################
- DNS ASK www.lu####dnd2kdnc.info
- DNS ASK www.f5####kkk4d.info
- DNS ASK www.hk####123ncs.info
- DNS ASK www.h7#####1wlsdn34fgv.info
- DNS ASK www.g1#####vns3sdsal.info
- DNS ASK www.microsoft.com
- DNS ASK ma#####oda.no-ip.biz
- DNS ASK www.in####1ongung.info
- DNS ASK www.bp##02.com
- ClassName: 'Indicator' WindowName: ''