Техническая информация
- '%PROGRAM_FILES%\Microsoft Ben\Hijack.exe'
- '<SYSTEM32>\taskkill.exe' /f /pid 3008
- '<SYSTEM32>\taskkill.exe' /f /pid 2964
- %TEMP%\download.html
- %PROGRAM_FILES%\Microsoft Ben\Hijack.exe
- %PROGRAM_FILES%\Microsoft Ben\Hijack.bat
- %PROGRAM_FILES%\Microsoft Ben\Hijack.bat в %PROGRAM_FILES%\Microsoft Ben\Hijack.com
- 'localhost':1036
- 'localhost':1035
- DNS ASK www.qi##ee.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'