Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WB32' = '"%HOMEPATH%\My Documents\Visual Studio SE\confu.exe" -a'
- скрытых файлов
- %HOMEPATH%\My Documents\Visual Studio SE\confu.exe -op
- %HOMEPATH%\My Documents\Visual Studio SE\nmbs.dll
- %HOMEPATH%\My Documents\Visual Studio SE\wb32.exe
- %HOMEPATH%\My Documents\Visual Studio SE\setfile.zip
- %HOMEPATH%\My Documents\Visual Studio SE\confu.exe
- %HOMEPATH%\My Documents\Visual Studio SE\setfile.zip
- 'ki######777.pnsweb.net.cn':80
- ki######777.pnsweb.net.cn/ls_install.asp?ma#########################
- DNS ASK ki######777.pnsweb.net.cn
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: 'FolderView'
- ClassName: 'WorkerW' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''