Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\NdisFileServices32] 'Start' = '00000002'
- <DRIVERS>\fohijn.sys
- <SYSTEM32>\wmdrtc32.dll
- <SYSTEM32>\wmdrtc32.dl_
- <DRIVERS>\fohijn.sys
- 'www.g1#####vns3sdsal.info':80
- 'www.in####1ongung.info':80
- 'www.bp##02.com':80
- www.g1#####vns3sdsal.info/t_100_v400/?rn#######################
- www.in####1ongung.info/t_100_v400/?rn#######################
- www.bp##02.com/t_100_v400/?rn#######################
- DNS ASK www.in####1ongung.info
- DNS ASK www.g1#####vns3sdsal.info
- DNS ASK www.microsoft.com
- DNS ASK www.bp##02.com
- ClassName: 'Indicator' WindowName: ''