Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Runonce' = '<SYSTEM32>\runouce.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'f86b1425' = '%APPDATA%\Microsoft\{8F7272E7-3D31-493C-A489-1B9BFC0C7CB4}\f86b1425.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'f86b1425' = '%APPDATA%\Microsoft\{8F7272E7-3D31-493C-A489-1B9BFC0C7CB4}\f86b1425.exe'
- %ProgramFiles%\Messenger\msmsgs.exe
- %ProgramFiles%\Internet Explorer\IEXPLORE.EXE
- %ProgramFiles%\Movie Maker\moviemk.exe
- %ProgramFiles%\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
- %ProgramFiles%\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
- %ProgramFiles%\Internet Explorer\Connection Wizard\icwtutor.exe
- %ProgramFiles%\Internet Explorer\Connection Wizard\icwrmind.exe
- %ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exe
- %ProgramFiles%\Internet Explorer\iedw.exe
- %ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exe
- %ProgramFiles%\Outlook Express\setup50.exe
- %ProgramFiles%\Outlook Express\oemig50.exe
- %ProgramFiles%\Outlook Express\wab.exe
- <STUBS_DIR>\test.exe
- %ProgramFiles%\Outlook Express\wabmig.exe
- %ProgramFiles%\NetMeeting\cb32.exe
- %ProgramFiles%\MSN\MSNCoreFiles\Install\msnsusii.exe
- %ProgramFiles%\NetMeeting\conf.exe
- %ProgramFiles%\Outlook Express\msimn.exe
- %ProgramFiles%\NetMeeting\wb32.exe
- %ProgramFiles%\FireFox\firefox.exe
- %ProgramFiles%\FireFox\crashreporter.exe
- %ProgramFiles%\FireFox\js.exe
- %ProgramFiles%\FireFox\nsinstall.exe
- %ProgramFiles%\FireFox\mangle.exe
- %CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE
- C:\Far2\Far.exe
- %CommonProgramFiles%\Microsoft Shared\DW\DWTRIG20.EXE
- %CommonProgramFiles%\Microsoft Shared\Speech\sapisvr.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe
- %ProgramFiles%\FireFox\xpt_dump.exe
- %ProgramFiles%\FireFox\xpidl.exe
- %ProgramFiles%\FireFox\xpt_link.exe
- %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exe
- %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe
- %ProgramFiles%\FireFox\shlibsign.exe
- %ProgramFiles%\FireFox\plugin-container.exe
- %ProgramFiles%\FireFox\uninstall\helper.exe
- %ProgramFiles%\FireFox\xpcshell.exe
- %ProgramFiles%\FireFox\updater.exe
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\wbem\wmiadap.exe
- <SYSTEM32>\ctfmon.exe
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\dllcache\icwconn2.exe.new
- <SYSTEM32>\dllcache\icwconn1.exe.new
- %ProgramFiles%\Outlook Express\wabmig.exe.new
- <SYSTEM32>\dllcache\icwrmind.exe.new
- <SYSTEM32>\dllcache\isignup.exe.new
- <SYSTEM32>\dllcache\inetwiz.exe.new
- <SYSTEM32>\dllcache\icwtutor.exe.new
- %ProgramFiles%\NetMeeting\wb32.exe.new
- %ProgramFiles%\NetMeeting\conf.exe.new
- %ProgramFiles%\NetMeeting\cb32.exe.new
- %ProgramFiles%\Outlook Express\msimn.exe.new
- %ProgramFiles%\Outlook Express\wab.exe.new
- %ProgramFiles%\Outlook Express\setup50.exe.new
- %ProgramFiles%\Outlook Express\oemig50.exe.new
- <SYSTEM32>\dllcache\iedw.exe.new
- <SYSTEM32>\dllcache\wabmig.exe.new
- <SYSTEM32>\dllcache\wab.exe.new
- <SYSTEM32>\dllcache\setup50.exe.new
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\connect[1].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\connect[2].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\connect[2].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\connect[1].htm
- <SYSTEM32>\dllcache\cb32.exe.new
- <SYSTEM32>\dllcache\moviemk.exe.new
- <SYSTEM32>\dllcache\iexplore.exe.new
- <SYSTEM32>\dllcache\conf.exe.new
- <SYSTEM32>\dllcache\oemig50.exe.new
- <SYSTEM32>\dllcache\msimn.exe.new
- <SYSTEM32>\dllcache\wb32.exe.new
- %ProgramFiles%\Movie Maker\moviemk.exe.new
- %ProgramFiles%\FireFox\chrome\browser\content\browser\certerror\readme.eml
- %ProgramFiles%\FireFox\chrome\browser\content\browser\readme.eml
- %CommonProgramFiles%\System\ado\readme.eml
- %ProgramFiles%\FireFox\chrome\browser\content\browser\feeds\readme.eml
- %CommonProgramFiles%\Microsoft Shared\Speech\sapisvr.exe.new
- %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe.new
- %ProgramFiles%\FireFox\chrome\browser\content\browser\safebrowsing\readme.eml
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\connect[1].htm
- %APPDATA%\Microsoft\{8F7272E7-3D31-493C-A489-1B9BFC0C7CB4}\f86b1425.exe
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- <SYSTEM32>\runouce.exe
- %CommonProgramFiles%\Microsoft Shared\Stationery\readme.eml
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\connect[1].htm
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\readme.eml
- %ProgramFiles%\FireFox\chrome\toolkit\content\global\readme.eml
- %ProgramFiles%\Internet Explorer\Connection Wizard\icwtutor.exe.new
- %ProgramFiles%\Internet Explorer\Connection Wizard\icwrmind.exe.new
- %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exe.new
- %ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exe.new
- %ProgramFiles%\Internet Explorer\iexplore.exe.new
- %ProgramFiles%\Internet Explorer\iedw.exe.new
- %ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exe.new
- <SYSTEM32>\dllcache\msinfo32.exe.new
- %ProgramFiles%\FireFox\chrome\toolkit\res\readme.eml
- %ProgramFiles%\FireFox\chrome\toolkit\content\global\cpow\readme.eml
- <SYSTEM32>\dllcache\sapisvr.exe.new
- %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe.new
- %ProgramFiles%\NetMeeting\readme.eml
- %ProgramFiles%\FireFox\defaults\profile\readme.eml
- <SYSTEM32>\runouce.exe
- %APPDATA%\Microsoft\{8F7272E7-3D31-493C-A489-1B9BFC0C7CB4}\f86b1425.exe
- 'jl####snlkfnkl.info':80
- 'jf####kbfkl.info':80
- 'ks###bsl.info':80
- 'hj#####kjhbkjhl.info':80
- 'kj###dskjl.info':80
- http://ks###bsl.info/lampi/connect.php
- http://jl####snlkfnkl.info/lampi/connect.php
- http://hj#####kjhbkjhl.info/lampi/connect.php
- http://kj###dskjl.info/lampi/connect.php
- DNS ASK bt###il.net.cn
- DNS ASK jl####snlkfnkl.info
- DNS ASK jf####kbfkl.info
- DNS ASK hj#####kjhbkjhl.info
- DNS ASK kj###dskjl.info
- DNS ASK ks###bsl.info
- ClassName: '' WindowName: ''