Техническая информация
- %TEMP%\30ef5.tmp
- %HOMEPATH%\Start Menu\Programs\Startup\adb.url
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cgi_personal_card[1]
- %WINDIR%\Debug\UserMode\userenv.log
- <SYSTEM32>\adb.url
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\cgi_personal_card[1]
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler11] 'Start' = '00000002'
- '%WINDIR%\sdqlyk \dwm.exe'
- '%WINDIR%\sdqlyk \dwm.exe' \dwm.exe
- %WINDIR%\Temp\29447.tmp
- %WINDIR%\sdqlyk \dwm.exe
- %TEMP%\30ef5.tmp
- %WINDIR%\sdqlyk \dwm.exe
- %WINDIR%\Temp\29447.tmp
- 'r.###ne.qq.com':80
- 'localhost':1041
- '21#.#1.76.125':6000
- 'localhost':1037
- r.###ne.qq.com/cgi-bin/user/cgi_personal_card?ui##
- DNS ASK r.###ne.qq.com
- ClassName: '(null)' WindowName: 'sdqlisagoodsoftware25709'