Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\sihekjqellek] 'Start' = '00000002'
- %TEMP%\DAT1.tmp.exe
- %TEMP%\DAT1.tmp.exe --SERVICE
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\getcfg[1].htm
- %TEMP%\DAT1.tmp.exe
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\getcfg[1].htm
- 'tr###polo.co.cc':80
- tr###polo.co.cc/trolllo/getcfg.php
- DNS ASK tr###polo.co.cc