Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\5jFqRu5Bcp] 'Start' = '00000002'
- '%TEMP%\CFК±№в.exe'
- %TEMP%\38c93.tmp
- <DRIVERS>\5jFqRu5Bcp.sys
- %CommonProgramFiles%\ysz.ini
- %TEMP%\CFК±№в.exe
- %TEMP%\36e7a.tmp
- %TEMP%\38203.tmp
- <DRIVERS>\5jFqRu5Bcp.sys
- %CommonProgramFiles%\ysz.ini
- %TEMP%\38c93.tmp
- %TEMP%\36e7a.tmp
- %TEMP%\38203.tmp
- '12#.#25.114.144':80
- 'localhost':1035
- 12#.#25.114.144/zhangsanysq/blog/item/1ae7324c39cc68c19d8204c7.html
- DNS ASK hi.##idu.com
- DNS ASK 91##wg.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'