Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'systeo' = '<SYSTEM32>\svchost.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'V559Wly2' = 'rundll32.exe V559Wly2.dll,Jinrux'
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\rundll32.exe' V559Wly2.dll,Jinrux
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\V559Wly2.dll
- 'r.###ne.qq.com':80
- 'localhost':1039
- http://r.###ne.qq.com/cgi-bin/user/cgi_personal_card?ui##################
- DNS ASK r.###ne.qq.com