Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{1759941D-142A-4063-AEFB-91043C2EFDB8}] 'stubpath' = ''
- <SYSTEM32>\invhwkmle.exe
- C:\GoClean.exe
- C:\server.exe
- <SYSTEM32>\userinit.exe
- <SYSTEM32>\userinit.exe
- %TEMP%\GoC2.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\upversion2[1].dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\g-ad-bottom2[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\g-ad-top2[1].htm
- %TEMP%\109750_res.tmp
- C:\GoClean.exe
- C:\server.exe
- <SYSTEM32>\invhwkmle.exe_lang.ini
- <SYSTEM32>\invhwkmle.exe
- C:\GoClean.exe
- C:\server.exe
- 'localhost':1038
- 'www.go###t.co.kr':80
- '<IP-адрес в локальной сети>':80
- 'www.go##st.kr':80
- www.go###t.co.kr/goclean/g-ad-bottom2.htm
- www.go###t.co.kr/goclean/g-ad-top2.htm
- www.go##st.kr/goclean/upversion2.dat
- DNS ASK www.go###t.co.kr
- DNS ASK www.go##st.kr
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''