Техническая информация
- <SYSTEM32>\MSINET.OCX
- <SYSTEM32>\MSCOMCTL.OCX
- <SYSTEM32>\COMDLG32.OCX
- <SYSTEM32>\wbem\XpdEc6d3Zj2tCceI3v.css
- C:\mlekaocYUmaae\HielDjixmHUfdeewc.exe
- %TEMP%\80EB2F5C
- C:\ProgramData\MieuaZienatyr\BueNoasediaz.exe
- C:\mlekaocYUmaae\HielDjixmHUfdeewc.exe
- <DRIVERS>\etc\hosts
- <SYSTEM32>\wbem\XpdEc6d3Zj2tCceI3v.css в C:\ProgramData\MieuaZienatyr\BueNoasediaz.exe
- <DRIVERS>\etc\hosts
- 'localhost':1036
- 'ci######ongans.blogspot.com':80
- 'dr###rme.com':80
- 'localhost':1040
- 'de####myhomee.com':80
- http://ci######ongans.blogspot.com/
- http://dr###rme.com/
- http://www.de####myhomee.com/ via de####myhomee.com
- DNS ASK ci######ongans.blogspot.com
- DNS ASK dr###rme.com
- DNS ASK www.de####myhomee.com
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- 'C:\ProgramData\MieuaZienatyr\BueNoasediaz.exe'
- 'C:\mlekaocYUmaae\HielDjixmHUfdeewc.exe'
- '<SYSTEM32>\cmd.exe' /c icacls <DRIVERS>\etc\hosts /reset
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -nohome