Техническая информация
- C:\ZcomMagSubscribe-100-2264.exe
- C:\SVCTHOS.exe
- C:\ZcomMagSubscribe-100-2264.exe (загружен из сети Интернет)
- <SYSTEM32>\cmd.exe /c ""kill.bat""
- <Текущая директория>\kill.bat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ZcomMagSubscribe-100-2264[1].exe
- C:\ZcomMagSubscribe-100-2264.exe
- C:\xjjy.dll
- C:\SVCTHOS.exe
- C:\SVCTHOS.exe
- C:\xjjy.dll
- %TEMP%\~DF243F.tmp
- 'zc####l.zcominc.com':80
- 'localhost':1035
- zc####l.zcominc.com/union/ZcomMagSubscribe-100-2264.exe
- DNS ASK zc####l.zcominc.com
- ClassName: '' WindowName: 'Zcom ?????????? 2007 Bata6 ????'
- ClassName: '' WindowName: 'Funshion'
- ClassName: '' WindowName: 'Zcom ?????????? 2007 Bata6 ???? '
- ClassName: '' WindowName: 'UUSee ???????? 2008 '
- ClassName: '' WindowName: 'UUSee ???????? 2008'
- ClassName: '' WindowName: 'Funshion 1.5.1.2 Beta ????'
- ClassName: '' WindowName: 'PPS v2.6.83.5300 Final ???????? '
- ClassName: '' WindowName: 'PPS v2.6.83.5300 Final ????????'
- ClassName: '' WindowName: '????????????'
- ClassName: '' WindowName: 'Funshion 1.5.1.2 Beta ???? '
- ClassName: '' WindowName: '????????'