Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Ias] 'Start' = '00000002'
- <SYSTEM32>\svchost.exe -k netsvcs
- C:\log.txt
- <SYSTEM32>\WinX86.log
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\0[1].jpg
- %TEMP%\kb-208140.tmp
- <SYSTEM32>\bak8011252.log
- %TEMP%\kb-205953.tmp
- %TEMP%\kb-206937.tmp
- %TEMP%\kb-208140.tmp в %TEMP%\ui208140.tmp
- %TEMP%\kb-206937.tmp в <SYSTEM32>\DUData.dll
- %TEMP%\kb-205953.tmp в %WINDIR%\ime\$MicoroSoft~X86.cpl
- 'jj.#ml.cn':80
- 'te####01.3322.org':4653
- jj.#ml.cn/temp/0.jpg
- DNS ASK jj.#ml.cn
- DNS ASK te####01.3322.org