Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SysDriver32' = '%WINDIR%\krnl32.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\list1[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\list2[1].txt
- %WINDIR%\krnl32.exe
- %WINDIR%\drv32.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\list2[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\list1[1].txt
- 'pl####onvert.com':80
- pl####onvert.com/spl/list2.txt
- pl####onvert.com/spl/list1.txt
- DNS ASK pl####onvert.com
- ClassName: 'Indicator' WindowName: ''