Техническая информация
- '%WINDIR%\explorer.exe' http://bl##.#ina.com.cn/qqhdbz
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\qqhdbz[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\qqhdbz[2]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\go[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\qqhdbz[2]
- <SYSTEM32>\superecYweVd.sys
- <SYSTEM32>\superecZcIQA.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\qqhdbz[1]
- %WINDIR%\SkinH_EL.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\qqhdbz[2]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\qqhdbz[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\qqhdbz[1]
- <SYSTEM32>\superecZcIQA.sys
- <SYSTEM32>\superecYweVd.sys
- 'localhost':1039
- 'www.yy.com':80
- 'localhost':1035
- 'bl##.#ina.com.cn':80
- www.yy.com/go.html
- bl##.#ina.com.cn/qqhdbz
- DNS ASK www.yy.com
- DNS ASK bl##.#ina.com.cn
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'