Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\137fdfa2] 'Start' = '00000002'
- <SYSTEM32>\rundll32.exe "%CommonProgramFiles%\Microsoft Shared\Triedit\137fdfa2.dll",ServiceEntry
- %TEMP%\RCX1.tmp
- %CommonProgramFiles%\Microsoft Shared\Triedit\137fdfa2.dll
- %TEMP%\1ad61_res.zip
- %TEMP%\1ad61_res.dll
- %TEMP%\1ad61_res.dll
- %TEMP%\1ad61_res.zip
- 'je####o.3322.org':8000
- DNS ASK je####o.3322.org