Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\EventSystemRoot] 'Start' = '00000002'
- '%WINDIR%\QQmon.exe'
- '<SYSTEM32>\svchost.exe' -k imgsvc
- '<SYSTEM32>\regini.exe' 223.htr
- '<SYSTEM32>\wscript.exe' "%WINDIR%\2345.vbe"
- ClassName: 'pediy06' WindowName: '(null)'
- ClassName: 'GBDYLLO' WindowName: '(null)'
- ClassName: 'OLLYDBG' WindowName: '(null)'
- C:\WinTemp.ini
- %PROGRAM_FILES%\Google\Google v6.html
- %WINDIR%\223.htr
- %WINDIR%\QQmon.exe
- %WINDIR%\2345.vbe
- %WINDIR%\ShortCutTool.dll
- %PROGRAM_FILES%\Google\Google v6.html
- %WINDIR%\223.htr
- %WINDIR%\2345.vbe
- C:\WinTemp.ini
- %WINDIR%\ShortCutTool.dll
- 'fm####.linkpc.net':3313
- 'fm###2.gicp.net':3311
- DNS ASK fm####.linkpc.net
- DNS ASK fm###2.gicp.net
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'