Техническая информация
- '%TEMP%\CFОЁ°®.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\baidu[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\youxicaitu[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\baidu[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\baidu[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ct[1].htm
- %TEMP%\CFОЁ°®ёЁЦъЛµГч.txt
- %TEMP%\CFОЁ°®.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\cftiyanfu[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\zg1[1].txt
- 'www.cf###anfu.com':80
- '12#.#25.114.144':80
- 'www.ba###pan.com':80
- 'localhost':1036
- 'localhost':1038
- 12#.#25.114.144/baidu?wo#########
- 12#.#25.114.144/baidu?wo###########
- 12#.#25.114.144/baidu?wo#######
- www.cf###anfu.com/youxicaitu/youxicaitu.htm
- www.cf###anfu.com/zg1.txt
- www.ba###pan.com/web/cftiyanfu.htm
- www.cf###anfu.com/jiemiancaitu/ct.htm
- DNS ASK www.cf###anfu.com
- DNS ASK www.ba##u.com
- DNS ASK www.91##wg.com
- DNS ASK www.ba###pan.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'