Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'hsearch' = '%PROGRAM_FILES%\hsearch\hsmain.exe'
- %PROGRAM_FILES%\hsearch\hsmain.exe
- %PROGRAM_FILES%\hsearch\hsmain.exe (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\hsmain[1].exe
- %PROGRAM_FILES%\hsearch\hsmain.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\hsearch[1].dll
- %PROGRAM_FILES%\hsearch\hsearch.dll
- 'hs###ch.co.kr':80
- hs###ch.co.kr/down/hsmain.exe
- hs###ch.co.kr/down/hsearch.dll
- DNS ASK hs###ch.co.kr