Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '%WINDIR%\svchost.exe'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\waseem[1].js
- %WINDIR%\softlink.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\waseem[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\desktop.ini
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\waseem[1].js
- %TEMP%\MMBPlayer\plugy.dll
- %TEMP%\MMBPlayer\g_hideshow.dll
- %TEMP%\MMBPlayer\Internet.dll
- %TEMP%\MMBPlayer\softlink.ini
- %TEMP%\MMBPlayer\PowerDIR.dll
- %TEMP%\MMBPlayer\foldy.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\waseem[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\waseem[1].js
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\waseem[1].js
- 'fi###.hpage.com':80
- 'localhost':1035
- fi###.hpage.com/001686/06/html/waseem.js
- fi###.hpage.com/001704/80/html/waseem.js
- DNS ASK fi###.hpage.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'