Техническая информация
- [<HKCU>\SYSTEM\CurrentControlSet\Services\59255D24] 'ImagePath' = '<SYSTEM32>\403B6022.EXE -d'
- [<HKLM>\SYSTEM\ControlSet001\Services\59255D24] 'ImagePath' = '<SYSTEM32>\403B6022.EXE -d'
- [<HKLM>\SYSTEM\ControlSet001\Services\59255D24] 'Start' = '00000002'
- <SYSTEM32>\403B6022.EXE -d
- <SYSTEM32>\winlogon.exe
- <SYSTEM32>\sd3dfs.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\update[1].txt
- <SYSTEM32>\jdjf7ls.dat1
- <SYSTEM32>\403B6022.EXE
- <SYSTEM32>\A1783B24.DLL
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\active[1].asp
- 'ck.##or2.com':80
- 'localhost':1037
- ck.##or2.com/gan//update.txt
- ck.##or2.com/gan//active.asp
- DNS ASK ck.##or2.com
- ClassName: '#32770' WindowName: '????????'
- ClassName: '' WindowName: '?????????????????? 6.0: ????'