Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Automatic LiveUpdate] 'Start' = '00000002'
- '<SYSTEM32>\Down.exe'
- %WINDIR%\Explorer.EXE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\newA[1].htm
- <SYSTEM32>\sysinfo2033043~1.info
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\leftinfo[1].htm
- <SYSTEM32>\TrVDll.dll
- <SYSTEM32>\srvchost.dll
- <SYSTEM32>\Down.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\leftinfo[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\newA[1].htm
- '21#.#47.226.102':80
- 21#.#47.226.102/testzy/leftinfo.htm
- 21#.#47.226.102/testzy/newA.htm
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'