Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\JAVA 6.5 Servcie Sun] 'ImagePath' = '<SYSTEM32>\sun\java\java.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\JAVA 6.5 Servcie Sun] 'Start' = '00000002'
- '<SYSTEM32>\ntvdm.exe' -f -i1
- '<SYSTEM32>\sun\java\java.exe'
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs2.tmp
- <SYSTEM32>\sun\java\jdk.exe
- <SYSTEM32>\sun\java\java.exe
- <SYSTEM32>\google_guid.dat
- <SYSTEM32>\google_guid.dat
- %WINDIR%\Temp\scs2.tmp
- %WINDIR%\Temp\scs1.tmp
- 'ig####e.imblog.in':80
- 'ig####e.imblog.in':10001
- 'iw###.vicp.cc':80
- http://iw###.vicp.cc/jdk.exe
- DNS ASK iw###.imbbs.in
- DNS ASK ig####e.imblog.in
- DNS ASK iw###.vicp.cc
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-b5c.b60.390001'