Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WaitHint] 'Start' = '00000002'
- <SYSTEM32>\SEHQC.EXE /install /silent
- <SYSTEM32>\net1.exe start WaitHint
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\DWZTRQLCEWOFBW.DLL"
- <SYSTEM32>\DASYBLHZ.DLL
- <DRIVERS>\PMDDLZFP.DAT
- <SYSTEM32>\SEHQC.EXE
- <SYSTEM32>\GCOGPMTHOZJGLEB.DLL
- <SYSTEM32>\EPWBPL.INI
- <SYSTEM32>\8u1mk8w7.dll
- <SYSTEM32>\wbem\KQFUHD.DLL
- <SYSTEM32>\DWZTRQLCEWOFBW.DLL
- 'ad.##kead.com':80
- 'www.pc###o.com.cn':80
- ad.##kead.com/start.asp?id##
- www.pc###o.com.cn/
- DNS ASK ad.##kead.com
- DNS ASK www.pc###o.com.cn
- ClassName: 'MS_WINHELP' WindowName: ''