Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157c}] 'Exec' = 'http://a.zhaol.com'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'navapvsc' = '<SYSTEM32>\navapvsc.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'conumie' = '<SYSTEM32>\conumie.exe'
- [<HKCU>\Software\Microsoft\Internet Explorer\Extensions\{6713E8D2-850A-101B-AFC0-4210102A8DA7}] 'EXEC' = 'http://sms.ufo2008.com'
- '<SYSTEM32>\ftp.exe' -s:<SYSTEM32>\333.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\in[1].htm
- <SYSTEM32>\333.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\update[1].txt
- <SYSTEM32>\333.txt
- 'localhost':1038
- 'www.zh##l.com':80
- 'localhost':1035
- 'www.zh##l.com':21
- www.zh##l.com/in.htm
- www.zh##l.com/update.txt
- DNS ASK www.zh##l.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''