Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'profree' = '%ProgramFiles%\profree.exe'
- '%ProgramFiles%\profree.exe'
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\response[1].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\response[1].asp
- %ProgramFiles%\profree.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\go_large[1].php
- 'xa#.com':80
- 'localhost':1041
- 'au##.#earch.msn.com':80
- 'cl####yleyou.com':80
- 'ad#.ly':80
- 'localhost':1036
- 'pr##ree.net':80
- 'localhost':1039
- http://cl####yleyou.com/data/seo.php
- http://au##.#earch.msn.com/response.asp?MT###########################
- http://xa#.com/web_gear/chat/go_large.php?id##########
- http://ad#.ly/1ACU2w
- http://pr##ree.net/
- DNS ASK cl####yleyou.com
- DNS ASK au##.#earch.msn.com
- DNS ASK xa#.com
- DNS ASK ad#.ly
- DNS ASK pr##ree.net
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''