Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\MFC] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- <DRIVERS>\etc\newhost.txt
- <SYSTEM32>\1037\mfc71.dll
- <DRIVERS>\etc\newhost.txt
- 'al####-google.cn':80
- 'go######s.g.doubleclick.net':80
- 'rj##.com.cn':80
- '10##lexa.cn':80
- al####-google.cn/guanli/list.txt
- 10##lexa.cn/up/1.txt
- 10##lexa.cn/fa/200906.asp?a=#################################
- DNS ASK al####-google.cn
- DNS ASK go######s.g.doubleclick.net
- DNS ASK rj##.com.cn
- DNS ASK 10##lexa.cn