Техническая информация
- '<SYSTEM32>\svehosd.exe'
- '<SYSTEM32>\crass.exe'
- '<SYSTEM32>\sohu.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tt336[2]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tt336[1]
- <SYSTEM32>\GroupPolicy\user\Scripts\script.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\1705313832[2]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\1705313832[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\thread[1].php
- <SYSTEM32>\GroupPolicy\gpt.ini
- %WINDIR%\KB2639418.log
- C:\ev8.ini
- <SYSTEM32>\sohu.exe
- %WINDIR%\Temp\svchost.exe
- <SYSTEM32>\svehosd.exe
- <SYSTEM32>\crass.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\1705313832[1]
- <DRIVERS>\etc\hosts
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tt336[1]
- <SYSTEM32>\GroupPolicy\user\Scripts\script.ini в <SYSTEM32>\GroupPolicy\user\Scripts\scripts.ini
- 'k4####p.f3322.org':1604
- 'yy.com':80
- 'localhost':1040
- 'localhost':1036
- 'www.tt##6.com':80
- yy.com/5336/1705313832
- www.tt##6.com/thread.php?fi####
- www.tt##6.com/
- DNS ASK yy.com
- DNS ASK k4####p.f3322.org
- DNS ASK www.tt##6.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''