Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Memory Check' = ''
- '%PROGRAM_FILES%\Microsoft_Patch.exe'
- '%PROGRAM_FILES%\Microsoft_Patch.exe' (загружен из сети Интернет)
- '<SYSTEM32>\net1.exe' STOP PERSFW
- '<SYSTEM32>\net1.exe' STOP NAVAPSVC
- '<SYSTEM32>\net1.exe' STOP AVPCC
- '<SYSTEM32>\net1.exe' STOP AVSYNMGR
- '<SYSTEM32>\net1.exe' STOP VSMON
- '<SYSTEM32>\net.exe' STOP PERSFW
- '<SYSTEM32>\net.exe' STOP NAVAPSVC
- '<SYSTEM32>\net.exe' STOP AVPCC
- '<SYSTEM32>\net.exe' STOP AVSYNMGR
- '<SYSTEM32>\net.exe' STOP VSMON
- NAVAPW32.EXE
- GUARD.EXE
- fsav.exe
- ntvdm.exe
- mpftray.exe
- AVGCTRL.EXE
- outpost.exe
- ZONEALARM.EXE
- zapro.exe
- AVSYNMGR.EXE
- AVP32.EXE
- AVPM.EXE
- AVP.EXE
- AVPCC.EXE
- %PROGRAM_FILES%\Microsoft_Patch.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\s[1].exe
- %WINDIR%\MemChck.exe
- 'hu###e.ath.cx':80
- 'localhost':1037
- hu###e.ath.cx/s.exe
- DNS ASK hu###e.ath.cx