Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Hpzwcfgs' = '%APPDATA%\Roaming\Hpzwcfg\Hpzwcfg.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MacromediaFlashs' = '%APPDATA%\Roaming\MacromediaFlash\MacromediaFlash.exe'
- '%APPDATA%\Roaming\Hpzwcfg\Hpzwcfg.exe'
- '%APPDATA%\Roaming\MacromediaFlash\hpz.exe'
- '%APPDATA%\Roaming\MacromediaFlash\MacromediaFlash.exe'
- Библиотека-обработчик для всех процессов: %APPDATA%\Roaming\Hpzwcfg\hooks.dll
- %APPDATA%\Roaming\Hpzwcfg\hooks.dll
- %APPDATA%\Roaming\Hpzwcfg\funcs.dll
- %APPDATA%\Roaming\Hpzwcfg\Hpzwcfg_.tmp
- %APPDATA%\Roaming\Hpzwcfg\Hpzwcfg.exe
- %APPDATA%\Roaming\MacromediaFlash\funcs.dll
- %APPDATA%\Roaming\MacromediaFlash\hpz.exe
- %APPDATA%\Roaming\MacromediaFlash\MacromediaFlash_.tmp
- %APPDATA%\Roaming\MacromediaFlash\MacromediaFlash.exe
- DNS ASK sm###.uol.com.br
- DNS ASK dn#.##ftncsi.com
- DNS ASK sm###.bol.com.br
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'Hpzwcfgs'
- ClassName: '' WindowName: 'MacromediaFlashs'
- ClassName: 'Indicator' WindowName: ''