Техническая информация
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.cf##dao.com
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cfwudao[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cfwudao[2]
- <Текущая директория>\superec.ProcessMemory.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cfwudao[2]
- 'localhost':1041
- '12#.#25.114.144':80
- 'localhost':1037
- 'www.cf##dao.com':80
- 12#.#25.114.144/405675617/blog/item/a83c18ac07c592134a36d66b.html
- www.cf##dao.com/
- DNS ASK hi.##idu.com
- DNS ASK www.cf##dao.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'