Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\mjtthnkl] 'Start' = '00000002'
- %TEMP%\DAT1.tmp.exe --SERVICE
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\getcfg[1].htm
- %TEMP%\DAT1.tmp.exe
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\getcfg[1].htm
- 'bl####start13.com':80
- bl####start13.com/testovik/getcfg.php
- DNS ASK bl####start13.com
- '<IP-адрес в локальной сети>':1037