Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\abp480n5] 'Start' = '00000002'
- <SYSTEM32>\net1.exe start abp480n5
- %WINDIR%\sleep.exe 5
- <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6YQRA29M\osver[1].htm
- <DRIVERS>\winntd_.dat
- %WINDIR%\abp480n5s
- <SYSTEM32>\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6YQRA29M\osver[1].htm
- %WINDIR%\abp480n5s в <DRIVERS>\abp480n5.sys
- '85.##.94.134':80
- 85.##.94.134/msupdate/osver.php