Техническая информация
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\red_off1[1].txt
- %TEMP%\1.tmp
- <SYSTEM32>\redmodz.exe
- <SYSTEM32>\autokey.dll
- <SYSTEM32>\redmodz.exe
- 'co#####3.fileave.com':80
- 'localhost':1035
- co#####3.fileave.com/red_off1.txt
- DNS ASK co#####3.fileave.com
- ClassName: '' WindowName: 'Search Results'
- ClassName: '' WindowName: 'Windows Task Manager'
- ClassName: '' WindowName: 'Process Explorer - Sysinternals: www.sysinternals.com'
- ClassName: '' WindowName: 'DATA'
- ClassName: '' WindowName: 'Audition Online'
- ClassName: '' WindowName: 'config'
- ClassName: '' WindowName: 'Xtrap'
- ClassName: '' WindowName: 'autokey.dll'
- ClassName: '' WindowName: 'Sysinternals: www.sysinternals.com'
- ClassName: '' WindowName: 'Run'
- ClassName: '' WindowName: 'My Computer'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'WINDOWS'
- ClassName: 'PROCEXPL' WindowName: ''
- ClassName: '' WindowName: 'Process Explorer'
- ClassName: '' WindowName: 'Process Hacker'
- ClassName: '' WindowName: 'system32'