Техническая информация
- '%WINDIR%\zmxy.exe'
- '%WINDIR%\ФмГООчУО3РЮёДґуК¦.exe'
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\78072[1].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\k12[1].txt
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\k12[1].txt
- %WINDIR%\zmxy.exe
- %WINDIR%\ФмГООчУО3РЮёДґуК¦.exe
- %WINDIR%\SkinH_EL.dll
- %WINDIR%\WnUninst.ini
- %WINDIR%\SkinH_EL.dll
- %WINDIR%\zmxy.exe в %TEMP%\141828\...\TemporaryFile
- %WINDIR%\zmxy.exe
- 'ha#.#n666.cc':80
- 'ha#.##999888777.win':80
- 'www.43##.com':80
- 'localhost':1038
- '12##.ip138.com':80
- http://ha#.#n666.cc/k12.txt
- http://ha#.##999888777.win/k12.txt
- http://12##.ip138.com/ic.asp
- http://www.43##.com/flash/78072.htm
- DNS ASK ha#.#n666.cc
- DNS ASK ha#.##999888777.win
- DNS ASK 12##.ip138.com
- DNS ASK www.43##.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'WTWindow' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''