Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'drwatson.exe' = '%WINDIR%\system\drwatson.exe'
- '%WINDIR%\system\Rundll16.exe'
- '%WINDIR%\system\drwatson.exe'
- %WINDIR%\system\drwatson.exe
- %WINDIR%\system\rundll32~.hlp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\HomeEmpresa[1].jsp
- %WINDIR%\system\rundll32.hlp
- %WINDIR%\system\Rundll16.exe
- %WINDIR%\system\rundll32.dll
- 'www.bb.#om.br':80
- 'www.uo#.com.br':80
- 'localhost':1037
- www.bb.#om.br/appbb/portal/HomeEmpresa.jsp
- www.uo#.com.br/
- DNS ASK www.bb.#om.br
- DNS ASK www.uo#.com.br
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'NDDEAgnt' WindowName: 'NetDDE Agent'