Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Ias] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- C:\log.txt
- <SYSTEM32>\WinX86.log
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\6[1].jpg
- %TEMP%\kb-173421.tmp
- <SYSTEM32>\bak8011252.log
- %TEMP%\kb-172109.tmp
- %TEMP%\kb-172750.tmp
- %TEMP%\kb-173421.tmp в %TEMP%\ui173421.tmp
- %TEMP%\kb-172750.tmp в <SYSTEM32>\DUData.dll
- %TEMP%\kb-172109.tmp в %WINDIR%\ime\$MicoroSoft~X86.cpl
- 'jj.#ml.cn':80
- jj.#ml.cn/temp/6.jpg
- DNS ASK jj.#ml.cn