Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{92B1E726-2CEF-1445-8768-7695C7C9925F}' = ''
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\post[1].htm
- <SYSTEM32>\dddowner.vxd
- 'ba####or.32881.com':80
- ba####or.32881.com/count/post.asp
- DNS ASK ba####or.32881.com
- ClassName: 'ListBox' WindowName: 'dll_doudoudowner'