Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\omV4vNv1Kga] 'Start' = '00000002'
- %TEMP%\1c33d.tmp
- <DRIVERS>\omV4vNv1Kga.sys
- %TEMP%\1b987.tmp
- %TEMP%\1bf25.tmp
- %TEMP%\1c33d.tmp
- <DRIVERS>\omV4vNv1Kga.sys
- %TEMP%\1b987.tmp
- %TEMP%\1bf25.tmp
- 'hi.##idu.com':80
- hi.##idu.com/yu20/blog/item/f5aef8de0cba6340ccbf1a9c.html
- DNS ASK hi.##idu.com
- ClassName: 'Shell_TrayWnd' WindowName: ''