Техническая информация
- '<SYSTEM32>\regsvr32.exe' /s "%TEMP%\url_bho.dll"
- %WINDIR%\Explorer.EXE
- chrome.exe
- iexplore.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\list[1].dat
- %TEMP%\_url_list.xml
- %TEMP%\filter.dll
- %TEMP%\ParemTranEx.dll
- %TEMP%\server.dat
- %TEMP%\url_bho.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\list[1].dat
- 'ho##.txcm8.com':80
- ho##.txcm8.com/list.dat
- DNS ASK ho##.txcm8.com