Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WmdmPmSN] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\qjnoNa] 'Start' = '00000002'
- <SYSTEM32>\mspmsnsv.dll
- %WINDIR%\Temp\79EE100F.tmp
- %WINDIR%\Temp\37D43FEB.tmp
- <SYSTEM32>\qjnoNa.sys
- C:\Documents and Settings\Infortmp.txt
- <SYSTEM32>\26AD058C.tmp
- %WINDIR%\Temp\79EE100F.tmp
- %WINDIR%\Temp\37D43FEB.tmp
- C:\Documents and Settings\Infortmp.txt
- <SYSTEM32>\26AD058C.tmp
- 'go.###i7863afb.info':799
- 'go.###i78634tg.info':799
- '11#.#38.237.83':799
- 'p.###456.com':75
- 'ts.##ss520.com':799
- DNS ASK go.###i7863afb.info
- DNS ASK go.###i78634tg.info
- DNS ASK ts.##ss520.com
- DNS ASK www.ba##u.com
- DNS ASK p.###456.com