Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\aspnet_states] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\DSLserverorm] 'Start' = '00000002'
- '%TEMP%\100.exe'
- '<SYSTEM32>\iickie.exe'
- '%TEMP%\vip.exe'
- '<SYSTEM32>\yygeym.exe'
- <SYSTEM32>\yygeym.exe
- <SYSTEM32>\iickie.exe
- %TEMP%\vip.exe
- %TEMP%\100.exe
- %TEMP%\100.exe в %TEMP%\SOFTWARE.LOG
- 'ap#.#oho1z.com':80
- 'ge###.api520.com':1001
- 'cc.##i520.com':1002
- ap#.#oho1z.com/baohe/wb/update.txt
- DNS ASK ap#.#oho1z.com
- DNS ASK ge###.api520.com
- DNS ASK cc.##i520.com