Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\Tasks\conime.exe'
- %WINDIR%\Tasks\conime.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHelp360] 'Start' = '00000002'
- '<SYSTEM32>\WinHelp360.exe'
- '%WINDIR%\Tasks\conime.exe'
- '%TEMP%\122424.exe'
- '<SYSTEM32>\110.exe'
- '%TEMP%\216565.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\4989054611314520[1].txt
- C:\boot
- <SYSTEM32>\WinHelp360.exe
- <SYSTEM32>\110.exe
- %TEMP%\216565.exe
- %TEMP%\122424.exe
- <SYSTEM32>\WinHelp360.exe
- C:\boot
- %TEMP%\122424.exe
- %TEMP%\216565.exe в %TEMP%\SOFTWARE.LOG
- 'localhost':1052
- 'www.52###0520.org':80
- 'qw###2.vicp.net':9898
- 'localhost':1035
- '61.##0.194.24':3308
- www.52###0520.org/1/Count.asp?ma########################
- www.52###0520.org/4989054611314520.txt
- DNS ASK www.52###0520.org
- DNS ASK qw###2.vicp.net
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'