Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ctfmon.exe' = '<SYSTEM32>\ctfmon.exe'
- <SYSTEM32>\ctfmon.exe
- <SYSTEM32>\dllcache\ctfmon.exe
- '%WINDIR%\system\nwiz.exe'
- '<SYSTEM32>\ctfmon.exe'
- '<SYSTEM32>\cmd.exe' /c "%PROGRAM_FILES%\Clean.bat"
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.bl###.com:2002/gen/list1.html
- '<SYSTEM32>\taskkill.exe' /im ctfmon.exe /f
- <SYSTEM32>\ctfmon.exe
- %PROGRAM_FILES%\Clean.bat
- %TEMP%\~DFBE94.tmp
- %TEMP%\~DF24C.tmp
- %TEMP%\~DFD8CD.tmp
- %TEMP%\~DFA072.tmp
- %WINDIR%\Windows.log
- %WINDIR%\system\nwiz.exe
- %TEMP%\~DFA072.tmp
- %TEMP%\~DF24C.tmp
- %TEMP%\~DFBE94.tmp
- '12#.#25.114.144':80
- 'localhost':1041
- 'localhost':1039
- 'localhost':1036
- 'www.bl##o.com':2002
- 12#.#25.114.144/waterman%5F1/blog/item/459e1ac91122cd15be09e6a1.html
- 12#.#25.114.144/waterman%5F0/blog/item/71f88ecf7704e70493457e62.html
- DNS ASK hi.##idu.com
- DNS ASK www.bl##o.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''