Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6096E38F-5AC1-4391-8EC4-75DFA92FB33F}] 'Exec' = 'http://www.852456.com/'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6096E38F-5AC1-4391-8EC4-75DFA92FB31F}] 'Exec' = 'http://www.7m3w.cn/'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6096E38F-5AC1-4391-8EC4-75DFA92FB32F}] 'Exec' = 'http://www.2m2m2m.com/'
- '%WINDIR%\regedit.exe' /s reg.reg
- <SYSTEM32>\sex.ico
- <SYSTEM32>\1.ico
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\7m3w[1]
- <SYSTEM32>\852456.ico
- <SYSTEM32>\dy.ico
- <SYSTEM32>\reg.reg
- 'www.7m#w.cn':80
- 'www.85##56.com':80
- 'localhost':1036
- www.7m#w.cn/?fr#####
- DNS ASK www.7m#w.cn
- DNS ASK www.85##56.com
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'