Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft update service' = '%WINDIR%\Microsoft.NET\Framework\ocs.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\upd[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\upd[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\upd[2].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\upd[2].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\upd[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\upd[1].php
- %WINDIR%\Microsoft.NET\Framework\ocs.exe
- %WINDIR%\ani.swf
- %WINDIR%\ani.res
- %WINDIR%\ani.res
- 'ce##-a.com':80
- 'localhost':1036
- ce##-a.com/ver/upd.php?r=##########
- DNS ASK ce##-a.com
- ClassName: 'Shell_TrayWnd' WindowName: ''