Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Qfokzc oamwfa] 'Start' = '00000002'
- '%PROGRAM_FILES%\Ruaaoi iqqsp\Euaizwo.exe'
- '<SYSTEM32>\taskkill.exe' /f /im V3SP.exe
- '<SYSTEM32>\wscript.exe' "C:\3792.vbs"
- '<SYSTEM32>\taskkill.exe' /f /im V3Main.exe
- '<SYSTEM32>\taskkill.exe' /f /im Ksafetray.exe
- '<SYSTEM32>\taskkill.exe' /f /im mcagent.exe
- MCAGENT.EXE
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\1055069492[1]
- C:\3792.vbs
- %PROGRAM_FILES%\Ruaaoi iqqsp\Euaizwo.exe
- C:\3792.vbs
- 'us##.#zone.qq.com':80
- 'localhost':1040
- 'a1####3.3322.org':3195
- us##.#zone.qq.com/1055069492
- DNS ASK us##.#zone.qq.com
- DNS ASK a1####3.3322.org
- ClassName: '' WindowName: ''