Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '%WINDIR%\staconf.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '<SYSTEM32>\scvhost.exe'
- %WINDIR%\staconf.exe
- %WINDIR%\syswow64\scvhost.exe
- 'al####e.mooo.com':80
- 'an#####nterprises.com':80
- 'hu###omains.com':443
- http://www.an#####nterprises.com/news/date/avi/malibuclinic040209.php
- 'hu###omains.com':443
- DNS ASK al####e.mooo.com
- DNS ASK an#####nterprises.com
- DNS ASK hu###omains.com
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''