Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Configuration Manager' = '%WINDIR%\cfg32.exe'
- '%WINDIR%\cfg32.exe'
- '<SYSTEM32>\regsvr32.exe' /u /s %WINDIR%\cfg32r.dll
- '<SYSTEM32>\regsvr32.exe' /u /s %WINDIR%\cfg32o.dll
- '<SYSTEM32>\regsvr32.exe' /u /s %WINDIR%\cfg32s.dll
- %WINDIR%\cfg32s.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\parent[1].asp
- %WINDIR%\cfg32r.dll
- %WINDIR%\cfg32o.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\cache[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\start[1].asp
- %WINDIR%\cfg32.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bundle[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\config[1].asp
- 'www.mm##ke.com':80
- www.mm##ke.com/serve/cache.asp?se########################################################################
- www.mm##ke.com/app/parent.asp?r=####
- www.mm##ke.com/serve/bundle.asp?uu##########################################################################
- www.mm##ke.com/app/start.asp?r=####
- www.mm##ke.com/serve/config.asp?se########################################################################
- DNS ASK www.mm##ke.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'