Техническая информация
- %WINDIR%\service.exe
- %WINDIR%\explore.exe
- <SYSTEM32>\regsvr32.exe /s %WINDIR%\hnetcfg.dll
- <SYSTEM32>\regsvr32.exe /s %WINDIR%\vsflex3.ocx
- <SYSTEM32>\regsvr32.exe /s %WINDIR%\mswinsck.ocx
- %WINDIR%\hnetcfg.dll
- <SYSTEM32>\service.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\p[1].txt
- <SYSTEM32>\explore.exe
- %WINDIR%\service.exe
- %WINDIR%\explore.exe
- %WINDIR%\vsflex3.ocx
- %WINDIR%\mswinsck.ocx
- 'wy#.#rqr.net':80
- 'localhost':1035
- wy#.#rqr.net/p.txt
- DNS ASK wy#.#rqr.net
- '<IP-адрес в локальной сети>':1036
- ClassName: '' WindowName: 'Xcwyk_fwd1_6:'
- ClassName: '' WindowName: 'Xcwyk_fwd1_5:'
- ClassName: '' WindowName: 'Xcwyk_fwd1_4:'
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: '' WindowName: 'Xcwyk_fwd1_7:'
- ClassName: '' WindowName: 'Xcwyk_fwd1_0:'
- ClassName: '' WindowName: 'Xcwyk_fwd:'
- ClassName: '' WindowName: 'Xcwyk_bhjl:'
- ClassName: '' WindowName: 'Xcwyk_fwd1_3:'
- ClassName: '' WindowName: 'Xcwyk_fwd1_2:'
- ClassName: '' WindowName: 'Xcwyk_fwd1_1:'