Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'DDWRIN1S2S' = '%APPDATA%\HwoiooHitw.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'DDWRIN1S2S' = '%APPDATA%\HwoiooHitw.exe'
- %APPDATA%\winupdate.dat
- %APPDATA%\winup00.dat
- %APPDATA%\hwoioohitw.exe
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\hwoioohitw.exe.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\hwoioohitw.exe
- %APPDATA%\date.dat
- 'me###.net.br':80
- 'qu####uip.com.br':80
- 'io##.org.cn':80
- http://me###.net.br/
- http://www.qu####uip.com.br/
- http://www.io##.org.cn/libraries/pear/graph.php
- DNS ASK me###.net.br
- DNS ASK qu####uip.com.br
- DNS ASK io##.org.cn