Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\MediaCenter] 'Start' = '00000002'
- '%TEMP%\RarSFX0\2.exe'
- '%TEMP%\RarSFX0\1.exe'
- '<SYSTEM32>\svchost.exe' -k krnlsrvr
- '<SYSTEM32>\wscript.exe' "%TEMP%\RarSFX0\a.vbs"
- %TEMP%\RarSFX0\a.vbs
- <SYSTEM32>\Rnmcwpx.dll
- %TEMP%\RarSFX0\1.exe
- %TEMP%\RarSFX0\2.exe
- %TEMP%\RarSFX0\2.exe
- %TEMP%\RarSFX0\1.exe
- 'www.93##.org':80
- 'dn###d.3322.org':3721
- www.93##.org/2.txt
- DNS ASK www.93##.org
- DNS ASK dn###d.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'