Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'BonusCash' = '%PROGRAM_FILES%\BonusCash\BonusCash.exe'
- %PROGRAM_FILES%\BonusCash\BonusCash.exe
- <SYSTEM32>\regsvr32.exe /s "%PROGRAM_FILES%\BonusCash\BonusCash.dll"
- Библиотека-обработчик для всех процессов: %PROGRAM_FILES%\BonusCash\BonusCash.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\list[1].ini
- %PROGRAM_FILES%\BonusCash\list.ini
- %PROGRAM_FILES%\BonusCash\BonusCash.dll
- %PROGRAM_FILES%\BonusCash\BonusCash.exe
- %PROGRAM_FILES%\BonusCash\uninstall.exe
- 'www.bo###cash.co.kr':80
- 're####.bonuscash.co.kr':80
- www.bo###cash.co.kr/sys/eMgrList.asp
- re####.bonuscash.co.kr/install.asp?ve##########################################
- re####.bonuscash.co.kr/Update_bc1000/BonusCash.ini
- re####.bonuscash.co.kr/list.ini
- DNS ASK www.bo###cash.co.kr
- DNS ASK re####.bonuscash.co.kr
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''