Техническая информация
- '%TEMP%\1.tmp\zom.EXE'
- '<SYSTEM32>\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 2
- '<SYSTEM32>\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 8
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\zomboz.bat" "
- iexplore.exe
- %TEMP%\1.tmp\FapCF2.dll
- %TEMP%\1.tmp\zomboz.bat
- %TEMP%\1.tmp\zom.EXE
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\likecf12.blogspot[2]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\likecf12.blogspot[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\likecf12.blogspot[1]
- %TEMP%\1.tmp\zom.EXE
- %TEMP%\1.tmp\FapCF2.dll
- %TEMP%\1.tmp\zomboz.bat
- '93.##8.134.11':80
- 'li#####2.blogspot.com':80
- 'localhost':1037
- 'an####b.zapto.org':80
- li#####2.blogspot.com/
- 93.##8.134.11/
- an####b.zapto.org/
- DNS ASK li#####2.blogspot.com
- DNS ASK yandex.ru
- DNS ASK an####b.zapto.org
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''