Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe] 'Debugger' = '<SYSTEM32>\merfwci.exe'
- %WINDIR%\syswow64\merfwci.exe
- %WINDIR%\system\inetmon.vbs
- %APPDATA%\microsoft\windows\privacie\index.dat
- 'go.##tswap.com':80
- 'je##wap.com':443
- 'x1.#.lencr.org':80
- http://go.##tswap.com/
- http://je##wap.com/
- http://je##wap.com/feed.png
- http://je##wap.com/news.js
- http://x1.#.lencr.org/
- 'go.##tswap.com':443
- DNS ASK go.##tswap.com
- DNS ASK je##wap.com
- DNS ASK x1.#.lencr.org
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\system\inetmon.vbs"