Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\ufad-dns60\Parameters] 'ServiceDll' = '<SYSTEM32>\vcphBHfhoW.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\ufad-dns60] 'ImagePath' = '<SYSTEM32>\svchost.exe -k ufad-dns60'
- [<HKLM>\SYSTEM\ControlSet001\Services\ufad-dns60] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k ufad-dns60
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\Admin_Post[1].htm
- C:\hwivyrMmSYr.dll
- <SYSTEM32>\vcphBHfhoW.dll
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\Admin_Post[1].htm
- C:\hwivyrMmSYr.dll в <SYSTEM32>\vcphBHfhoW.dll
- 'tj.##nhucj.cn':80
- http://tj.##nhucj.cn/Admin_Post.Asp
- DNS ASK tj.##nhucj.cn