Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\1390bcs] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\1390bcs] 'ImagePath' = '<DRIVERS>\1390bcs.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\offcie.NetMSSQL viip01] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k "offcie.NetMSSQL viip01"
- <DRIVERS>\1390bcs.sys
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\vip01[1].txt
- <SYSTEM32>\mt4314dm.dll
- <SYSTEM32>\RCX1.tmp
- <SYSTEM32>\mt4314dm.dll
- <SYSTEM32>\RCX1.tmp в <SYSTEM32>\mt4314dm.dll
- '14.##6.5.163':80
- 14.##6.5.163/ip/vip01.txt