Техническая информация
- '%PROGRAM_FILES%\lb_bosom_6.exe'
- '%PROGRAM_FILES%\lb_bosom_6.exe' (загружен из сети Интернет)
- '<SYSTEM32>\ntsd.exe' -c q -pn aixinwen.exe
- '<SYSTEM32>\ntsd.exe' -c q -pn lb_bosom_6.exe
- %PROGRAM_FILES%\lb_bosom_6.exe
- 'do####ad.n152.com':80
- do####ad.n152.com/ndl.aspx?ui###########################
- DNS ASK do####ad.n152.com
- ClassName: 'Button' WindowName: '??????(&N) >'
- ClassName: '#32770' WindowName: '???? ???? '