Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mdhcp32] 'Startup' = 'WinStart2EX'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mdhcp32] 'DllName' = 'mdhcp32.dll'
- <SYSTEM32>\dll.dll
- <SYSTEM32>\crt.dat
- <Текущая директория>\sname
- <SYSTEM32>\shimg.dll
- <SYSTEM32>\dll.dll
- 'ja#l.de':80
- '78.##9.121.137':8014
- '74.##5.232.51':80
- ja#l.de/gweb/g2/bazooka.php?ne####################################
- DNS ASK ja#l.de
- DNS ASK www.google.com