Техническая информация
- %WINDIR%\Tasks\SA.DAT
- [<HKLM>\SYSTEM\ControlSet003\Services\Schedule] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\Schedule] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Schedule] 'Start' = '00000002'
- <DRIVERS>\beep.sys
- <SYSTEM32>\dllcache\beep.sys файлом <SYSTEM32>\dllcache\beep.sys.new
- <SYSTEM32>\svchost.exe -k Schedule
- <SYSTEM32>\hapfiv.dll
- <SYSTEM32>\dllcache\beep.sys.new
- <SYSTEM32>\0005069c.sys
- <SYSTEM32>\vbteko.dll
- 'mo###.ns3.name':8888
- 'ca####.mydad.info':8090
- DNS ASK mo###.ns3.name
- DNS ASK ca####.mydad.info