Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{3290769C-0471-11d2-AF11-00C04FA35D02}] 'StubPath' = '%WINDIR%\addins\winrar.exe'
- '%TEMP%\exe2exe.exe'
- '%TEMP%\exe1exe.exe'
- '%WINDIR%\regedit.exe' /s shmily.reg
- '%WINDIR%\regedit.exe' /s BD.reg
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "
- '<SYSTEM32>\wscript.exe' "%WINDIR%/addins/Mchicken.vbs"
- '<SYSTEM32>\find.exe' "2000"
- %WINDIR%\addins\winrar.exe
- %WINDIR%\addins\ver.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\login[1]
- %TEMP%\7ZSfx000.cmd
- %WINDIR%\addins\shmily.reg
- %WINDIR%\addins\Mchicken.vbs
- %TEMP%\exe2exe.exe
- %TEMP%\exe1exe.exe
- %WINDIR%\addins\360reg.bat
- %WINDIR%\addins\00C04FA35D02.vbs
- %WINDIR%\addins\win32shelldown.bat
- %WINDIR%\addins\shmily.reg
- %WINDIR%\addins\Mchicken.vbs
- %TEMP%\exe2exe.exe
- %TEMP%\7ZSfx000.cmd
- 'ui.###ogin2.qq.com':80
- 'localhost':1035
- ui.###ogin2.qq.com/cgi-bin/login?ap##############################################################################################################################################################
- DNS ASK ui.###ogin2.qq.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''