Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = '%WINDIR%\svchosts.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe %WINDIR%\svchosts.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\svchosts.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Generic Host Process' = '%WINDIR%\svchosts.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'Generic Host Process' = '%WINDIR%\svchosts.exe'
- <SYSTEM32>\cmd.exe /c <SYSTEM32>\del32.bat
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://
- <SYSTEM32>\del32.bat
- %WINDIR%\svchosts.exe
- <SYSTEM32>\ckl009.dat
- <SYSTEM32>\wsock.ini
- <SYSTEM32>\wsock.dll
- %WINDIR%\svchosts.exe
- <SYSTEM32>\wsock.ini
- 'je####go.no-ip.info':314
- 'localhost':1035
- DNS ASK je####go.no-ip.info
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '#32770' WindowName: 'Windows Security Alert'
- ClassName: '#32770' WindowName: 'Warning: Components Have Changed'
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'ThunderRT6FormDC' WindowName: 'xccxcxcxc66637'
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''