Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
- %PROGRAM_FILES%\Garss.exe "C:\Documents and Settings\QQCRT.DLL" Main
- C:\ЗїЧіУВКї.exe
- C:\Server.exe
- %WINDIR%\regedit.exe /s C:\1.reg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\DNFzhuang[1].html
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\6688wg[1]
- C:\1.reg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\DNFjuexing[1].html
- C:\ЗїЧіУВКї.exe
- C:\Server.exe
- %TEMP%\113656_res.tmp
- %PROGRAM_FILES%\Garss.exe
- C:\ЗїЧіУВКї.exe
- C:\Server.exe
- C:\1.reg
- 'we####20tt.gicp.net':8050
- 'www.66##wg.com':80
- 'localhost':1037
- www.66##wg.com/DNFjuexing.html
- www.66##wg.com/DNFzhuang.html
- www.66##wg.com/
- DNS ASK we####20tt.gicp.net
- DNS ASK www.66##wg.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''