Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'Explorer.exe <SYSTEM32>\blackice.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = '<SYSTEM32>\blackice.exe'
- %WINDIR%\Explorer.EXE
- NAVAPW32.EXE
- nod32.exe
- ccapp.exe
- AVP.EXE
- 360tray.exe
- ashAvast.exe
- AVP.COM
- <SYSTEM32>\blackice.ini
- <SYSTEM32>\kernel.dll
- <SYSTEM32>\blackice.exe
- <SYSTEM32>\blackice.exe
- <SYSTEM32>\blackice.ini
- 'fm###d.zj.com':80
- http://fm###d.zj.com/blackice3/url.txt
- DNS ASK fm###d.zj.com