Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'PointWay' = '%PROGRAM_FILES%\PointWay\ControlPointWay.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinIETools' = '"%PROGRAM_FILES%\Windows IE Tools\WinIETools.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'USPack' = '"%PROGRAM_FILES%\Utility Service Pack\USPack.exe"'
- <SYSTEM32>\regsvr32.exe /s "%PROGRAM_FILES%\PointWay\PointEx.dll"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\WinIETools[1].exe
- %PROGRAM_FILES%\Windows IE Tools\WinIETools.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\ControlPointWay[1].exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\PointEx[1].dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\USPack[1].exe
- %PROGRAM_FILES%\Utility Service Pack\USPack.exe
- 'ie###ls.co.kr':80
- 'us###k.co.kr':80
- 'po###way.co.kr':80
- ie###ls.co.kr/Application/WinIETools.exe
- po###way.co.kr/Info/Application/playgames/ControlPointWay.exe
- po###way.co.kr/Info/dll/PointEx.dll
- us###k.co.kr/Application/USPack.exe
- DNS ASK ie###ls.co.kr
- DNS ASK www.po###way.co.kr
- DNS ASK po###way.co.kr
- DNS ASK us###k.co.kr
- ClassName: 'WorkerW' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''