Техническая информация
- <SYSTEM32>\25DWa2DxUqsWn2O.exe
- <SYSTEM32>\ЦґРРDLL.EXE
- <SYSTEM32>\cmd.exe /c ""<SYSTEM32>\ЦґРРDLL.EXE.bat" "
- <SYSTEM32>\cmd.exe /c ""<SYSTEM32>\25DWa2DxUqsWn2O.exe.bat" "
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.so#8.cc
- %WINDIR%\20121023\8sy2qIeeIBaalu82\script\XlKankan.dll
- %WINDIR%\20121023\8sy2qIeeIBaalu82\script\regBHO.reg
- %WINDIR%\20121023\8sy2qIeeIBaalu82\script\reg.bat
- %WINDIR%\tao.ico
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\sou8[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\1[1].html
- %WINDIR%\20121023\58sIujd5DMU22esQ\smss.exe
- <SYSTEM32>\sougou.ime
- <SYSTEM32>\ЦґРРDLL.EXE
- <SYSTEM32>\ЦґРРDLL.dll
- <SYSTEM32>\25DWa2DxUqsWn2O.exe
- %WINDIR%\20121023\8sy2qIeeIBaalu82\script\script.vbs
- %WINDIR%\20121023\8sy2qIeeIBaalu82\script\script.exe
- %WINDIR%\20121023\i28HocltTGjHJN2M\DownFiles.exe
- 'localhost':1040
- 'www.so#8.cc':80
- 'localhost':1037
- 'www.s-##ay.tk':80
- www.so#8.cc/
- www.s-##ay.tk/1.html
- DNS ASK www.so#8.cc
- DNS ASK www.s-##ay.tk
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''