Техническая информация
- '%WINDIR%\Temp\HaoXy.exe'
- '<SYSTEM32>\wscript.exe' "%WINDIR%\temp\tc.vbs"
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\97dn[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\97wg[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\wgxzb[1]
- %WINDIR%\Temp\HaoXy.exe
- %WINDIR%\Temp\setup.ini
- %WINDIR%\Temp\speed.ini
- %WINDIR%\Temp\tc.vbs
- %WINDIR%\Temp\tc.vbs
- 'localhost':1040
- 'localhost':1042
- 'www.wg##b.net':80
- '12#.#25.114.144':80
- 'localhost':1038
- 'www.97##.com':80
- www.wg##b.net/?tc
- www.97##.com/?tc
- 12#.#25.114.144/haoxy2009/blog/item/4ddb6d1d226afaff1bd576fe.html
- DNS ASK www.wg##b.net
- DNS ASK www.97##.com
- DNS ASK hi.##idu.com
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'