Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHelp32] 'Start' = '00000002'
- '<SYSTEM32>\WinHelp32.exe'
- '%WINDIR%\2.exe'
- '%WINDIR%\1.exe'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- <SYSTEM32>\WinHelp32.exe
- %WINDIR%\1.exe
- %WINDIR%\2.exe
- <SYSTEM32>\WinHelp32.exe
- %WINDIR%\1.exe
- 'ha###13.dns1.us':8777
- 'ha######13.dynamic-dns.net':80
- ha######13.dynamic-dns.net/open.php
- DNS ASK ha###13.dns1.us
- DNS ASK ha######13.dynamic-dns.net
- ClassName: '18467-41' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''