Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Beep] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\Persist] 'Start' = '00000001'
- <DRIVERS>\beep.sys
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://www.23##.com/?14###
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://58.##.173.202/count/tj02.asp?id#####
- '<SYSTEM32>\rundll32.exe' uspx.dll look
- %WINDIR%\Explorer.EXE
- <DRIVERS>\Persist.sys
- <SYSTEM32>\usp.ini
- <SYSTEM32>\uspx.dll
- C:\Temp\new516.sys
- <SYSTEM32>\uspx.dll
- C:\Temp\new516.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tj02[1].asp
- C:\Temp\new516.sys
- 'www.23##.com':80
- 'localhost':1041
- 'tj.###shenqi.com':2345
- '18.###shenqi.com':2345
- 'localhost':1040
- '58.##.173.202':2345
- 'localhost':1036
- '58.##.173.202':80
- 'localhost':1038
- www.23##.com/?14###
- 58.##.173.202/count/tj02.asp?id#####
- DNS ASK tj.###shenqi.com
- DNS ASK 18.###shenqi.com
- DNS ASK www.23##.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''