Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Service 2,0,6,19' = '%TEMP%\qh562.exe'
- %TEMP%\100004.exe
- %TEMP%\qh562.exe
- %TEMP%\kingsoftkonline\KINSTALLERS_41_61290.exe /s
- %TEMP%\gamebrowser_1.0_lizhiheng_t101001.exe
- %TEMP%\CFФВУ°ёЁЦъ.exe
- %TEMP%\wiresion.exe
- %TEMP%\KINSTALLERS_41_61290.exe
- %TEMP%\kingsoftkonline\KINSTALLERS_41_61290.exe (загружен из сети Интернет)
- <SYSTEM32>\ping.exe 1.0.0.1 -n
- <SYSTEM32>\cmd.exe /c ""%TEMP%\8501.bat" "
- <SYSTEM32>\svchost.exe -k ImgSvc
- <SYSTEM32>\svchost.exe
- iexplore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\navigate.wiseie[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\list[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\version[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\getdata[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\88[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\go[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\list[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\urlfavs[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\web[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\go[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\hao123[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\sysgiflistl0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\syshtmlistl0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sysswflistl0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\syscomlistl0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\Sysadlistl0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\sysjslistl0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\similardomainsl0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\getdata[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\syswhiteadlist0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sysunionlistl0[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\syswhitepoplistl0[1].txt
- %HOMEPATH%\Desktop\Internet Explore.lnk
- %TEMP%\gamebrowser_1.0_lizhiheng_t101001.exe
- %TEMP%\KINSTALLERS_41_61290.exe
- %TEMP%\100004.exe
- %TEMP%\8501.bat
- %TEMP%\qh562.exe
- %TEMP%\wiresion.exe
- %TEMP%\nsr2.tmp\AdvSplash.dll
- %TEMP%\nsr2.tmp\Splash_start.bmp
- %TEMP%\CFФВУ°ёЁЦъ.exe
- %TEMP%\$filenumber.txt
- %TEMP%\$filenumbere.txt
- %HOMEPATH%\Start Menu\Programs\УОП·дЇААЖч\Р¶ФШ.lnk
- %HOMEPATH%\Start Menu\Programs\УОП·дЇААЖч\їЄЖфУОП·дЇААЖч.lnk
- %HOMEPATH%\Desktop\УОП·дЇААЖч.lnk
- %PROGRAM_FILES%\yxdown\IE.ico
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\s[1]
- %PROGRAM_FILES%\УОП·дЇААЖч\higamebrowser.exe
- %APPDATA%\gamebrowser\wisedb\searchegn.pied
- %APPDATA%\gamebrowser\configs.ini
- %APPDATA%\gamebrowser\wisedb\fmsg.pied
- %TEMP%\kingsoftkonline\KINSTALLERS_41_61290.exe.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\xz[1].htm
- %TEMP%\nsr2.tmp\AdvSplash.dll
- %TEMP%\nsr2.tmp\Splash_start.bmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\getdata[1]
- %TEMP%\$filenumbere.txt
- %TEMP%\$filenumber.txt
- %TEMP%\100004.exe
- %TEMP%\kingsoftkonline\KINSTALLERS_41_61290.exe.tmp в %TEMP%\kingsoftkonline\KINSTALLERS_41_61290.exe
- 'up####.wiseie.com':80
- 'localhost':1059
- 'na####te.wiseie.com':80
- 're####ct.wiseie.com':80
- 'st##.wiseie.com':80
- 'fo####.seemjab.com':19325
- 'www.yx##wn.com':80
- 'localhost':1063
- 'st####j.seemjab.com':30008
- 'xm##t.com':80
- 'localhost':1042
- 'bo.###a.net:8080':80
- 'localhost':1038
- 'ga##.wiseie.com':80
- 'tj.#x6xx.cn':519
- 'cd###.www.duba.net':80
- 'www.ba##u.com':80
- up####.wiseie.com/wisedb/similardomainsl0.txt
- up####.wiseie.com/wisedb/syswhiteadlist0.txt
- up####.wiseie.com/wisedb/syswhitepoplistl0.txt
- up####.wiseie.com/gamebrowser/version.txt
- www.yx##wn.com/ads/88.html
- st##.wiseie.com/getdata?id##
- up####.wiseie.com/wisedb/sysunionlistl0.txt
- up####.wiseie.com/wisedb/sysswflistl0.txt
- up####.wiseie.com/wisedb/Sysadlistl0.txt
- up####.wiseie.com/wisedb/syscomlistl0.txt
- up####.wiseie.com/wisedb/sysjslistl0.txt
- up####.wiseie.com/wisedb/syshtmlistl0.txt
- up####.wiseie.com/wisedb/sysgiflistl0.txt
- cd###.www.duba.net/duba/install/2011/ever/kavsetups_41_0.exe
- ga##.wiseie.com/data/urlfavs.txt
- www.ba##u.com/s?wd#
- bo.###a.net:8080/pagetracer2/duba/__utm.gif?01#######################################################################################################################
- xm##t.com/bd/MX/xz.htm?MX
- xm##t.com/bd/MX/b.php?go######
- ga##.wiseie.com/ads/list.txt
- re####ct.wiseie.com/go?ac##########################################
- ga##.wiseie.com/union/list.txt
- na####te.wiseie.com/?p=#################################################
- na####te.wiseie.com/web?z=#####################################################
- na####te.wiseie.com/tpl/hao123.htm
- re####ct.wiseie.com/go?ac##############################
- DNS ASK up####.wiseie.com
- DNS ASK re####ct.wiseie.com
- DNS ASK na####te.wiseie.com
- DNS ASK www.ta##ao.com
- DNS ASK fo####.seemjab.com
- DNS ASK st##.wiseie.com
- DNS ASK www.yx##wn.com
- DNS ASK cd###.www.duba.net
- DNS ASK xm##t.com
- DNS ASK bo.###a.net:8080
- DNS ASK www.ba##u.com
- DNS ASK st####j.seemjab.com
- DNS ASK tj.#x6xx.cn
- DNS ASK ga##.wiseie.com
- ClassName: '' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''