Техническая информация
- <SYSTEM32>\winlogon.exe
- <SYSTEM32>\winlogon.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\response[2].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\xzdz[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\response[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\gg[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\gg5[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\response[2].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\response[1].asp
- 'au##.#earch.msn.com':80
- 'za##511.com':80
- 'localhost':1039
- 'www.bl##o.com':2000
- 'www.tr##se.net':80
- au##.#earch.msn.com/response.asp?MT###########################
- za##511.com/t8.2.txt
- www.tr##se.net/xzdz.txt
- www.tr##se.net/gg.txt
- www.tr##se.net/gg5.txt
- DNS ASK au##.#earch.msn.com
- DNS ASK za##511.com
- DNS ASK www.bl##o.com
- DNS ASK www.tr##se.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''