Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SSVC] 'Start' = '00000002'
- <SYSTEM32>\sdb.exe (загружен из сети Интернет)
- <SYSTEM32>\sc.exe start SSVC
- <SYSTEM32>\sc.exe create SSVC binPath= %WINDIR%/system32/sdb.exe start= auto
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\sdb[1].exe
- %WINDIR%\sdb.exe
- %WINDIR%\comms.dll
- <SYSTEM32>\comms.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sdb[1].exe
- <SYSTEM32>\sdb.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\comms[1].dll
- 'dl###ud.info':80
- 'localhost':1037
- 'bc##ud.me':8118
- dl###ud.info/svc1/sdb.exe
- dl###ud.info/svc/comms.dll
- dl###ud.info/svc/sdb.exe
- DNS ASK dl###ud.info
- DNS ASK bc##ud.me
- '<IP-адрес в локальной сети>':1035