Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\W32Time] 'Start' = '00000002'
- '%TEMP%\yangzhou2030.3322.org ±ё·Э ±ё·Э ±ё·Э.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %TEMP%\qqЅШНјОґГьГы.jpg
- %PROGRAM_FILES%\NVIDIA\IBntEx.Dll
- %PROGRAM_FILES%\NVIDIA\IBntEx.OLE
- %TEMP%\yangzhou2030.3322.org ±ё·Э ±ё·Э ±ё·Э.exe
- %TEMP%\qqЅШНјОґГьГы.jpg
- %TEMP%\yangzhou2030.3322.org ±ё·Э ±ё·Э ±ё·Э.exe в %TEMP%\FK32.LOG
- 'ya#####u2030.3322.org':4455
- DNS ASK ya#####u2030.3322.org
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'opjkropioiasdjaieee'