Техническая информация
- %TEMP%\RarSFX0\IESTASS.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://sp###6.3322.org/hx/meinv/play888.htm
- %HOMEPATH%\Desktop\InternetЎЎExplorer.lnk
- %PROGRAM_FILES%\Internet Explorer\IEXPLFRE.EXE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\play888[1].htm
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\InternetЎЎExplorer.lnk
- %HOMEPATH%\Favorites\0056НшЦ·ґуИ«.lnk
- %TEMP%\RarSFX0\IESTASS.exe
- %TEMP%\RarSFX0\urlb.lnk
- %HOMEPATH%\Favorites\Л«ИЛРЎУОП·.lnk
- %HOMEPATH%\Favorites\ОТ°®ТфАЦНш.lnk
- %HOMEPATH%\Desktop\InternetЎЎExplorer.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\InternetЎЎExplorer.lnk
- %HOMEPATH%\Favorites\0056НшЦ·ґуИ«.lnk
- %HOMEPATH%\Favorites\ОТ°®ТфАЦНш.lnk
- %HOMEPATH%\Favorites\Л«ИЛРЎУОП·.lnk
- %TEMP%\RarSFX0\urlb.lnk
- %TEMP%\RarSFX0\IESTASS.exe
- 'ku###3.3322.org':80
- 'sp###6.3322.org':80
- 'localhost':1035
- ku###3.3322.org/wwwww/count.asp?ma#############################################################################
- sp###6.3322.org/hx/meinv/play888.htm
- DNS ASK ku###3.3322.org
- DNS ASK sp###6.3322.org
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''