Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\National] 'Start' = '00000002'
- Редактора реестра (RegEdit)
- <SYSTEM32>\HSUpdate.exe
- %WINDIR%\system\Click14.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\5923wg[1]
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\count[1].asp
- <SYSTEM32>\HSUpdate.exe
- %WINDIR%\system\Click14.exe
- %TEMP%\j1.dll
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\count[1].asp
- %WINDIR%\system\Click14.exe
- 'www.he###2012.com':80
- 'www.xi###xueche.com':1212
- 'localhost':1035
- 'www.59##wg.com':80
- www.he###2012.com/count.asp?ma#######################################
- www.59##wg.com/
- DNS ASK www.he###2012.com
- DNS ASK www.xi###xueche.com
- DNS ASK www.59##wg.com
- '<IP-адрес в локальной сети>':1036
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Afx:400000:b:10011:1900015:0' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''