Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Ias] 'Start' = '00000002'
- <SYSTEM32>\svchost.exe -k netsvcs
- %APPDATA%\Iasid.dll
- <SYSTEM32>\Iasid.dll.right.tlb
- <SYSTEM32>\Ias.m_rmvb.bat
- <SYSTEM32>\Ias.r_rmvb.bat
- <SYSTEM32>\Iasid.dll.move.tlb
- C:\RECYCLER\recyl.exe
- <SYSTEM32>\cc.exetem.tem
- <SYSTEM32>\Iasid.dll.temp.tlb
- %TEMP%\148937cnna.txt
- 'wk####3.3322.org':2010
- DNS ASK wk####3.3322.org